Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Question Modification and Deletion

Medium 5.4 CWE-639Fixed in 11.2.8
ID
WPSEC-2026-0465
Plugin
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (quiz-master-next)
Affected
all versions before 11.2.8
Remediation
Update to 11.2.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weakness
CWE-639
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker on WPSec AttackSurface
Fix released
Published

Description

The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 11.2.7 via the question save REST endpoint and linked question handling. This is due to authorization being checked only against the request's quiz ID rather than the quiz each affected question actually belongs to. This makes it possible for authenticated attackers, with Contributor-level access and above who own any quiz, to overwrite or delete questions in quizzes belonging to other authors, either directly by question ID or by linking them.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0