CVE-2026-14824
Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz.
| Vendor | unknown |
| Product | quiz and survey master (qsm) |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown quiz and survey master (qsm)
Be the first to know when new unknown vulnerabilities affecting unknown quiz and survey master (qsm) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Quiz and Survey Master (QSM)
0 < 11.2.2
References
Credits
Meher Sudhakar Abbireddi WPScan