# Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Question Modification and Deletion

- **ID:** WPSEC-2026-0465
- **Plugin:** Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (`quiz-master-next`), https://wordpress.org/plugins/quiz-master-next/
- **Affected versions:** all versions before 11.2.8
- **Fixed in:** 11.2.8 (Update to 11.2.8 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/quiz-master-next
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0465/

## Description

The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 11.2.7 via the question save REST endpoint and linked question handling. This is due to authorization being checked only against the request's quiz ID rather than the quiz each affected question actually belongs to. This makes it possible for authenticated attackers, with Contributor-level access and above who own any quiz, to overwrite or delete questions in quizzes belonging to other authors, either directly by question ID or by linking them.

## References

- https://wpsec.com/vuln/WPSEC-2026-0465/
- https://plugins.svn.wordpress.org/quiz-master-next/tags/11.2.8/
- https://wordpress.org/plugins/quiz-master-next/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0465/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
