Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesQuiz and Survey Master (QSM)

Quiz and Survey Master (QSM) vulnerabilities

Quiz and Survey Master (QSM) has 42 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.

Known vulnerabilities
42
Active installs
40,000+
Latest version
11.2.7
Last updated
24 Sep 2026
Most recent
7 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-104391
Medium 6.5Up to 11.2.7No fixed version yet15 h ago
Broken access control
CVE-2026-79615
Low 2.7Before 11.2.4Fixed in 11.2.428 Aug 2026
Broken access control
CVE-2026-14825
Low 2.7Before 11.2.4Fixed in 11.2.419 Aug 2026
Broken access control
CVE-2026-14826
Low 2.7Before 11.2.4Fixed in 11.2.419 Aug 2026
SQL injection
CVE-2026-15963
Medium 6.5Up to 11.2.1Fixed in a later version (latest 11.2.7)16 Aug 2026
Cross-site scripting (XSS)
CVE-2026-11780
Medium 6.4Up to 11.2.1Fixed in a later version (latest 11.2.7)16 Aug 2026
Cross-site scripting (XSS)
CVE-2026-14824
Medium 4.8Before 11.2.2Fixed in 11.2.24 Aug 2026
Broken access control
CVE-2026-14821
Low 2.7Before 11.1.5Fixed in 11.1.528 Jul 2026
Sensitive data exposure
CVE-2026-14820
Medium 5.3Before 11.1.3Fixed in 11.1.327 Jul 2026
SQL injection
CVE-2026-13767
Medium 6.5Up to 11.2.0Fixed in a later version (latest 11.2.7)16 Jul 2026
Broken access control
CVE-2026-9230
Medium 4.3Up to 11.1.4Fixed in a later version (latest 11.2.7)3 Jul 2026
Broken access control
CVE-2026-9233
Medium 4.3Up to 11.1.4Fixed in a later version (latest 11.2.7)27 Jun 2026
SQL injection
CVE-2026-6448
Medium 4.9Up to 11.1.2Fixed in a later version (latest 11.2.7)6 Jun 2026
Security weakness
CVE-2026-5797
Medium 5.3Up to 11.1.0Fixed in a later version (latest 11.2.7)17 Apr 2026
SQL injection
CVE-2026-2412
Medium 6.5Up to 10.3.5Fixed in a later version (latest 11.2.7)23 Mar 2026
SQL injection
CVE-2025-9318
Medium 6.5Before 10.3.2Fixed in 10.3.26 Jan 2026
Broken access control
CVE-2025-9637
Medium 6.5Before 10.3.2Fixed in 10.3.26 Jan 2026
Broken access control
CVE-2025-9294
Medium 4.3Before 10.3.2Fixed in 10.3.26 Jan 2026
Cross-site request forgery (CSRF)
CVE-2025-6790
Medium 4.3Before 10.2.3Fixed in 10.2.314 Aug 2025
Cross-site scripting (XSS)
CVE-2024-10679
Medium 6.1Before 9.2.1Fixed in 9.2.125 Mar 2025
Cross-site scripting (XSS)
CVE-2024-8758
Medium 4.8Before 9.1.3Fixed in 9.1.323 Sep 2024
Cross-site scripting (XSS)
CVE-2024-6879
Medium 4.7Before 9.1.1Fixed in 9.1.126 Aug 2024
Cross-site scripting (XSS)
CVE-2024-6390
Medium 5.9Before 9.1.0Fixed in 9.1.03 Aug 2024
Cross-site scripting (XSS)
CVE-2024-6025
Medium 5.4Before 9.0.5Fixed in 9.0.511 Jul 2024
SQL injection
CVE-2024-5606
High 8.8Before 9.0.2Fixed in 9.0.22 Jul 2024
Cross-site scripting (XSS)
CVE-2024-4934
Medium 5.5Before 9.0.2Fixed in 9.0.21 Jul 2024
SQL injection
CVE-2024-3592
Critical 9.9Before 9.0.2Fixed in 9.0.27 Jun 2024
Cross-site request forgery (CSRF)
CVE-2023-26524
Medium 4.3Up to 8.0.10Fixed in a later version (latest 11.2.7)13 Nov 2023
Cross-site request forgery (CSRF)
CVE-2023-0292
Medium 5.4Up to 8.0.8Fixed in a later version (latest 11.2.7)9 Jun 2023
Broken access control
CVE-2023-0291
High 7.2Up to 8.0.8Fixed in a later version (latest 11.2.7)9 Jun 2023
Cross-site request forgery (CSRF)
CVE-2022-46862
Medium 4.3Before 8.0.8Fixed in 8.0.814 Feb 2023
Sensitive data exposure
CVE-2022-42883
Medium 5.3Up to 7.3.10Fixed in a later version (latest 11.2.7)18 Nov 2022
Cross-site scripting (XSS)
CVE-2022-40698
Medium 5.4Before 7.3.11Fixed in 7.3.1118 Nov 2022
Broken access control
CVE-2022-41652
Medium 6.5Before 7.3.11Fixed in 7.3.1118 Nov 2022
Cross-site scripting (XSS)
CVE-2021-36905
Medium 5.4Before 7.3.5Fixed in 7.3.517 Nov 2022
Broken access control
CVE-2021-36906
Low 2.7Up to 7.3.6Fixed in a later version (latest 11.2.7)3 Nov 2022
SQL injection
CVE-2021-36898
High 7.5Up to 7.3.4Fixed in a later version (latest 11.2.7)28 Oct 2022
Cross-site scripting (XSS)
CVE-2021-36864
Low 3.4Up to 7.3.4Fixed in a later version (latest 11.2.7)28 Oct 2022
Cross-site scripting (XSS)
CVE-2021-36863
Medium 5.4Up to 7.3.4Fixed in a later version (latest 11.2.7)28 Oct 2022
Broken access control
CVE-2021-36865
Low 3.8Up to 7.3.4Fixed in a later version (latest 11.2.7)30 Sep 2022
Cross-site scripting (XSS)
CVE-2019-17599
Medium 6.1Before 6.3.5Fixed in 6.3.513 Dec 2019
Cross-site scripting (XSS)
CVE-2019-9575
Medium 6.1Not yet publishedCheck for an update5 Mar 2019
Read the published descriptions
CVE-2026-104391, 7 Oct 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7. CVE record
CVE-2026-79615, 28 Aug 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. CVE record
CVE-2026-14825, 19 Aug 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. CVE record
CVE-2026-14826, 19 Aug 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users. CVE record
CVE-2026-15963, 16 Aug 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-11780, 16 Aug 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-14824, 4 Aug 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz. CVE record
CVE-2026-14821, 28 Jul 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. CVE record
CVE-2026-14820, 27 Jul 2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3. CVE record
CVE-2026-13767, 16 Jul 2026
The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in qsm_options_questions_tab_content() at line 143, where the stored page IDs are interpolated into an IN() clause via implode() with no $wpdb->prepare() and no integer casting. This makes it possible for authenticated attackers, with Author-level access and above (who can own a quiz they are entitled to edit), to plant a SQL payload that is executed second-order whenever any user (including an administrator) views the quiz's Questions tab, allowing them to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-9230, 3 Jul 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify quizzes they do not own, overwrite quiz results pages, and reroute quiz-result notification emails to attacker-controlled addresses. An attacker first calls the /quiz/structure endpoint with an arbitrary victim quiz ID to obtain a valid nonce bound to that quiz ID and their own user ID, then presents that nonce to the /quizzes/{id}/emails save endpoint, which accepts it without verifying quiz ownership. CVE record
CVE-2026-9233, 27 Jun 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create, modify, and delete quiz output templates stored in the mlw_quiz_output_templates database table, including storing unsanitized HTML content such as arbitrary script tags. CVE record
CVE-2026-6448, 6 Jun 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. If the secret key is exposed, this can be exploited by lower-privileged users. CVE record
CVE-2026-5797, 17 Apr 2026
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks. CVE record
CVE-2026-2412, 23 Mar 2026
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the merged_question parameter does not prevent SQL metacharacters like ), OR, AND, and # from being included in the value, which is then directly concatenated into a SQL IN() clause without using $wpdb->prepare() or casting values to integers. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-9318, 6 Jan 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-9637, 6 Jan 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view the details of unpublished, private, or password-protected quizzes, as well as submit file responses to questions from those quizzes, which allow file upload. CVE record
CVE-2025-9294, 6 Jan 2026
The Quiz and Survey Master (QSM) - Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete quiz results. CVE record
CVE-2025-6790, 14 Aug 2025
The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. CVE record
CVE-2024-10679, 25 Mar 2025
The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-8758, 23 Sep 2024
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-6879, 26 Aug 2024
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks. CVE record
CVE-2024-6390, 3 Aug 2024
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks CVE record
CVE-2024-6025, 11 Jul 2024
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks CVE record
CVE-2024-5606, 2 Jul 2024
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role CVE record
CVE-2024-4934, 1 Jul 2024
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE record
CVE-2024-3592, 7 Jun 2024
The Quiz And Survey Master - Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2024-5606 appears to be a duplicate of this issue. CVE record
CVE-2023-26524, 13 Nov 2023
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master - Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions. CVE record
CVE-2023-0292, 9 Jun 2023
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-0291, 9 Jun 2023
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files. CVE record
CVE-2022-46862, 14 Feb 2023
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master - Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions. CVE record
CVE-2022-42883, 18 Nov 2022
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. CVE record
CVE-2022-40698, 18 Nov 2022
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. CVE record
CVE-2022-41652, 18 Nov 2022
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. CVE record
CVE-2021-36905, 17 Nov 2022
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
CVE-2021-36906, 3 Nov 2022
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. CVE record
CVE-2021-36898, 28 Oct 2022
Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
CVE-2021-36864, 28 Oct 2022
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
CVE-2021-36863, 28 Oct 2022
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. CVE record
CVE-2021-36865, 30 Sep 2022
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. CVE record
CVE-2019-17599, 13 Dec 2019
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL. CVE record
CVE-2019-9575, 5 Mar 2019
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. CVE record

What to do if you run Quiz and Survey Master (QSM)

If you run Quiz and Survey Master (QSM), open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Quiz and Survey Master (QSM) vulnerabilities

Free. We email you when a new vulnerability is published for Quiz and Survey Master (QSM), usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support