Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.7 - Unauthenticated Arbitrary Shortcode Execution via 'result_id' and 'qsm_unique_key' Parameters

High 7.3 CWE-94Fixed in 11.2.8
ID
WPSEC-2026-0466
Plugin
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (quiz-master-next)
Affected
from 11.2.6 before 11.2.8
Remediation
Update to 11.2.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness
CWE-94
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker on WPSec AttackSurface
Fix released
Published

Description

The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'qsm_unique_key' and 'result_id' parameters in versions 11.2.6 to 11.2.7. This is due to the plugin storing a visitor-supplied 'qsm_unique_key' as the result's unique ID and later concatenating the 'result_id' value into a shortcode string passed to do_shortcode() without removing shortcode delimiters. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes on the site.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0