HomeWordPress vulnerabilitiesQuiz and Survey Master (QSM)
Quiz and Survey Master (QSM) vulnerabilities
Quiz and Survey Master (QSM) has 42 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.
- Known vulnerabilities
- 42
- Active installs
- 40,000+
- Latest version
- 11.2.7
- Last updated
- 24 Sep 2026
- Most recent
- 7 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-104391 | Medium 6.5 | Up to 11.2.7 | No fixed version yet | 15 h ago |
| Broken access control CVE-2026-79615 | Low 2.7 | Before 11.2.4 | Fixed in 11.2.4 | 28 Aug 2026 |
| Broken access control CVE-2026-14825 | Low 2.7 | Before 11.2.4 | Fixed in 11.2.4 | 19 Aug 2026 |
| Broken access control CVE-2026-14826 | Low 2.7 | Before 11.2.4 | Fixed in 11.2.4 | 19 Aug 2026 |
| SQL injection CVE-2026-15963 | Medium 6.5 | Up to 11.2.1 | Fixed in a later version (latest 11.2.7) | 16 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-11780 | Medium 6.4 | Up to 11.2.1 | Fixed in a later version (latest 11.2.7) | 16 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-14824 | Medium 4.8 | Before 11.2.2 | Fixed in 11.2.2 | 4 Aug 2026 |
| Broken access control CVE-2026-14821 | Low 2.7 | Before 11.1.5 | Fixed in 11.1.5 | 28 Jul 2026 |
| Sensitive data exposure CVE-2026-14820 | Medium 5.3 | Before 11.1.3 | Fixed in 11.1.3 | 27 Jul 2026 |
| SQL injection CVE-2026-13767 | Medium 6.5 | Up to 11.2.0 | Fixed in a later version (latest 11.2.7) | 16 Jul 2026 |
| Broken access control CVE-2026-9230 | Medium 4.3 | Up to 11.1.4 | Fixed in a later version (latest 11.2.7) | 3 Jul 2026 |
| Broken access control CVE-2026-9233 | Medium 4.3 | Up to 11.1.4 | Fixed in a later version (latest 11.2.7) | 27 Jun 2026 |
| SQL injection CVE-2026-6448 | Medium 4.9 | Up to 11.1.2 | Fixed in a later version (latest 11.2.7) | 6 Jun 2026 |
| Security weakness CVE-2026-5797 | Medium 5.3 | Up to 11.1.0 | Fixed in a later version (latest 11.2.7) | 17 Apr 2026 |
| SQL injection CVE-2026-2412 | Medium 6.5 | Up to 10.3.5 | Fixed in a later version (latest 11.2.7) | 23 Mar 2026 |
| SQL injection CVE-2025-9318 | Medium 6.5 | Before 10.3.2 | Fixed in 10.3.2 | 6 Jan 2026 |
| Broken access control CVE-2025-9637 | Medium 6.5 | Before 10.3.2 | Fixed in 10.3.2 | 6 Jan 2026 |
| Broken access control CVE-2025-9294 | Medium 4.3 | Before 10.3.2 | Fixed in 10.3.2 | 6 Jan 2026 |
| Cross-site request forgery (CSRF) CVE-2025-6790 | Medium 4.3 | Before 10.2.3 | Fixed in 10.2.3 | 14 Aug 2025 |
| Cross-site scripting (XSS) CVE-2024-10679 | Medium 6.1 | Before 9.2.1 | Fixed in 9.2.1 | 25 Mar 2025 |
| Cross-site scripting (XSS) CVE-2024-8758 | Medium 4.8 | Before 9.1.3 | Fixed in 9.1.3 | 23 Sep 2024 |
| Cross-site scripting (XSS) CVE-2024-6879 | Medium 4.7 | Before 9.1.1 | Fixed in 9.1.1 | 26 Aug 2024 |
| Cross-site scripting (XSS) CVE-2024-6390 | Medium 5.9 | Before 9.1.0 | Fixed in 9.1.0 | 3 Aug 2024 |
| Cross-site scripting (XSS) CVE-2024-6025 | Medium 5.4 | Before 9.0.5 | Fixed in 9.0.5 | 11 Jul 2024 |
| SQL injection CVE-2024-5606 | High 8.8 | Before 9.0.2 | Fixed in 9.0.2 | 2 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-4934 | Medium 5.5 | Before 9.0.2 | Fixed in 9.0.2 | 1 Jul 2024 |
| SQL injection CVE-2024-3592 | Critical 9.9 | Before 9.0.2 | Fixed in 9.0.2 | 7 Jun 2024 |
| Cross-site request forgery (CSRF) CVE-2023-26524 | Medium 4.3 | Up to 8.0.10 | Fixed in a later version (latest 11.2.7) | 13 Nov 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0292 | Medium 5.4 | Up to 8.0.8 | Fixed in a later version (latest 11.2.7) | 9 Jun 2023 |
| Broken access control CVE-2023-0291 | High 7.2 | Up to 8.0.8 | Fixed in a later version (latest 11.2.7) | 9 Jun 2023 |
| Cross-site request forgery (CSRF) CVE-2022-46862 | Medium 4.3 | Before 8.0.8 | Fixed in 8.0.8 | 14 Feb 2023 |
| Sensitive data exposure CVE-2022-42883 | Medium 5.3 | Up to 7.3.10 | Fixed in a later version (latest 11.2.7) | 18 Nov 2022 |
| Cross-site scripting (XSS) CVE-2022-40698 | Medium 5.4 | Before 7.3.11 | Fixed in 7.3.11 | 18 Nov 2022 |
| Broken access control CVE-2022-41652 | Medium 6.5 | Before 7.3.11 | Fixed in 7.3.11 | 18 Nov 2022 |
| Cross-site scripting (XSS) CVE-2021-36905 | Medium 5.4 | Before 7.3.5 | Fixed in 7.3.5 | 17 Nov 2022 |
| Broken access control CVE-2021-36906 | Low 2.7 | Up to 7.3.6 | Fixed in a later version (latest 11.2.7) | 3 Nov 2022 |
| SQL injection CVE-2021-36898 | High 7.5 | Up to 7.3.4 | Fixed in a later version (latest 11.2.7) | 28 Oct 2022 |
| Cross-site scripting (XSS) CVE-2021-36864 | Low 3.4 | Up to 7.3.4 | Fixed in a later version (latest 11.2.7) | 28 Oct 2022 |
| Cross-site scripting (XSS) CVE-2021-36863 | Medium 5.4 | Up to 7.3.4 | Fixed in a later version (latest 11.2.7) | 28 Oct 2022 |
| Broken access control CVE-2021-36865 | Low 3.8 | Up to 7.3.4 | Fixed in a later version (latest 11.2.7) | 30 Sep 2022 |
| Cross-site scripting (XSS) CVE-2019-17599 | Medium 6.1 | Before 6.3.5 | Fixed in 6.3.5 | 13 Dec 2019 |
| Cross-site scripting (XSS) CVE-2019-9575 | Medium 6.1 | Not yet published | Check for an update | 5 Mar 2019 |
Read the published descriptions
- CVE-2026-104391, 7 Oct 2026
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7. CVE record
- CVE-2026-79615, 28 Aug 2026
- The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. CVE record
- CVE-2026-14825, 19 Aug 2026
- The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. CVE record
- CVE-2026-14826, 19 Aug 2026
- The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users. CVE record
- CVE-2026-15963, 16 Aug 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-11780, 16 Aug 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-14824, 4 Aug 2026
- The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz. CVE record
- CVE-2026-14821, 28 Jul 2026
- The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. CVE record
- CVE-2026-14820, 27 Jul 2026
- The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3. CVE record
- CVE-2026-13767, 16 Jul 2026
- The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in qsm_options_questions_tab_content() at line 143, where the stored page IDs are interpolated into an IN() clause via implode() with no $wpdb->prepare() and no integer casting. This makes it possible for authenticated attackers, with Author-level access and above (who can own a quiz they are entitled to edit), to plant a SQL payload that is executed second-order whenever any user (including an administrator) views the quiz's Questions tab, allowing them to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-9230, 3 Jul 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify quizzes they do not own, overwrite quiz results pages, and reroute quiz-result notification emails to attacker-controlled addresses. An attacker first calls the /quiz/structure endpoint with an arbitrary victim quiz ID to obtain a valid nonce bound to that quiz ID and their own user ID, then presents that nonce to the /quizzes/{id}/emails save endpoint, which accepts it without verifying quiz ownership. CVE record
- CVE-2026-9233, 27 Jun 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create, modify, and delete quiz output templates stored in the mlw_quiz_output_templates database table, including storing unsanitized HTML content such as arbitrary script tags. CVE record
- CVE-2026-6448, 6 Jun 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. If the secret key is exposed, this can be exploited by lower-privileged users. CVE record
- CVE-2026-5797, 17 Apr 2026
- The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks. CVE record
- CVE-2026-2412, 23 Mar 2026
- The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the merged_question parameter does not prevent SQL metacharacters like ), OR, AND, and # from being included in the value, which is then directly concatenated into a SQL IN() clause without using $wpdb->prepare() or casting values to integers. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-9318, 6 Jan 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-9637, 6 Jan 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view the details of unpublished, private, or password-protected quizzes, as well as submit file responses to questions from those quizzes, which allow file upload. CVE record
- CVE-2025-9294, 6 Jan 2026
- The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete quiz results. CVE record
- CVE-2025-6790, 14 Aug 2025
- The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. CVE record
- CVE-2024-10679, 25 Mar 2025
- The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-8758, 23 Sep 2024
- The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-6879, 26 Aug 2024
- The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks. CVE record
- CVE-2024-6390, 3 Aug 2024
- The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks CVE record
- CVE-2024-6025, 11 Jul 2024
- The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks CVE record
- CVE-2024-5606, 2 Jul 2024
- The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role CVE record
- CVE-2024-4934, 1 Jul 2024
- The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE record
- CVE-2024-3592, 7 Jun 2024
- The Quiz And Survey Master - Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2024-5606 appears to be a duplicate of this issue. CVE record
- CVE-2023-26524, 13 Nov 2023
- Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master - Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions. CVE record
- CVE-2023-0292, 9 Jun 2023
- The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-0291, 9 Jun 2023
- The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files. CVE record
- CVE-2022-46862, 14 Feb 2023
- Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master - Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions. CVE record
- CVE-2022-42883, 18 Nov 2022
- Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. CVE record
- CVE-2022-40698, 18 Nov 2022
- Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. CVE record
- CVE-2022-41652, 18 Nov 2022
- Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. CVE record
- CVE-2021-36905, 17 Nov 2022
- Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
- CVE-2021-36906, 3 Nov 2022
- Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. CVE record
- CVE-2021-36898, 28 Oct 2022
- Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
- CVE-2021-36864, 28 Oct 2022
- Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
- CVE-2021-36863, 28 Oct 2022
- Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
- CVE-2021-36865, 30 Sep 2022
- Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. CVE record
- CVE-2019-17599, 13 Dec 2019
- The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL. CVE record
- CVE-2019-9575, 5 Mar 2019
- The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. CVE record
What to do if you run Quiz and Survey Master (QSM)
If you run Quiz and Survey Master (QSM), open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Quiz and Survey Master (QSM) vulnerabilities
Free. We email you when a new vulnerability is published for Quiz and Survey Master (QSM), usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.