CVE-2026-14820
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
| Vendor | unknown |
| Product | quiz and survey master (qsm) |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown quiz and survey master (qsm)
Be the first to know when new unknown vulnerabilities affecting unknown quiz and survey master (qsm) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Quiz and Survey Master (QSM)
0 < 11.1.3
References
Credits
Ahmad Mubarak Alanazi WPScan