๐Ÿ” CVE Alert

CVE-2026-14826

UNKNOWN 0.0

Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.

Vendor unknown
Product quiz and survey master (qsm)
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown quiz and survey master (qsm)

Be the first to know when new unknown vulnerabilities affecting unknown quiz and survey master (qsm) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Quiz and Survey Master (QSM)
0 < 11.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bb9cac20-4df5-4834-89f0-746a5eab20ea/

Credits

Revanth Hari Narayana Matte WPScan