CVE-2026-79615
Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
| Vendor | unknown |
| Product | quiz and survey master (qsm) |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown quiz and survey master (qsm)
Be the first to know when new unknown vulnerabilities affecting unknown quiz and survey master (qsm) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Quiz and Survey Master (QSM)
0 < 11.2.4
References
Credits
Shikhali Jamalzade WPScan