Vulnerabilities / Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker / WPSEC-2026-0465
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Question Modification and Deletion
Medium 5.4
CWE-639Fixed in 11.2.8
- ID
- WPSEC-2026-0465
- Plugin
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (quiz-master-next)
- Affected
- all versions before 11.2.8
- Remediation
- Update to 11.2.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Weakness
- CWE-639
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker on WPSec AttackSurface
- Fix released
- Published
Description
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 11.2.7 via the question save REST endpoint and linked question handling. This is due to authorization being checked only against the request's quiz ID rather than the quiz each affected question actually belongs to. This makes it possible for authenticated attackers, with Contributor-level access and above who own any quiz, to overwrite or delete questions in quizzes belonging to other authors, either directly by question ID or by linking them.
References
- https://wpsec.com/vuln/WPSEC-2026-0465/
- https://plugins.svn.wordpress.org/quiz-master-next/tags/11.2.8/
- https://wordpress.org/plugins/quiz-master-next/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS