{
 "id": "WPSEC-2026-0465",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0465/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0465/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0465/index.md",
 "title": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Question Modification and Deletion",
 "description": "The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 11.2.7 via the question save REST endpoint and linked question handling. This is due to authorization being checked only against the request's quiz ID rather than the quiz each affected question actually belongs to. This makes it possible for authenticated attackers, with Contributor-level access and above who own any quiz, to overwrite or delete questions in quizzes belonging to other authors, either directly by question ID or by linking them.",
 "plugin": {
  "slug": "quiz-master-next",
  "name": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker",
  "full_name": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker",
  "wordpress_org": "https://wordpress.org/plugins/quiz-master-next/",
  "advisories_url": "https://wpsec.com/vuln/plugin/quiz-master-next/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/quiz-master-next"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "11.2.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 11.2.8"
  ]
 },
 "introduced_in": null,
 "fixed_in": "11.2.8",
 "remediation": "Update to 11.2.8 or later.",
 "fix_released": "2026-10-05T15:12:29+00:00",
 "published": "2026-10-06T18:46:14+00:00",
 "updated": "2026-10-06T18:33:27.988060+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0465/",
  "https://plugins.svn.wordpress.org/quiz-master-next/tags/11.2.8/",
  "https://wordpress.org/plugins/quiz-master-next/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/quiz-master-next",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}