๐Ÿ” CVE Alert

CVE-2026-14820

UNKNOWN 0.0

Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.

Vendor unknown
Product quiz and survey master (qsm)
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown quiz and survey master (qsm)

Be the first to know when new unknown vulnerabilities affecting unknown quiz and survey master (qsm) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Quiz and Survey Master (QSM)
0 < 11.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/22af8c73-8147-4205-8285-a35881f2d041/

Credits

Ahmad Mubarak Alanazi WPScan