Vulnerabilities / Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker / WPSEC-2026-0466
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.7 - Unauthenticated Arbitrary Shortcode Execution via 'result_id' and 'qsm_unique_key' Parameters
High 7.3
CWE-94Fixed in 11.2.8
- ID
- WPSEC-2026-0466
- Plugin
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (quiz-master-next)
- Affected
- from 11.2.6 before 11.2.8
- Remediation
- Update to 11.2.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weakness
- CWE-94
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker on WPSec AttackSurface
- Fix released
- Published
Description
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'qsm_unique_key' and 'result_id' parameters in versions 11.2.6 to 11.2.7. This is due to the plugin storing a visitor-supplied 'qsm_unique_key' as the result's unique ID and later concatenating the 'result_id' value into a shortcode string passed to do_shortcode() without removing shortcode delimiters. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes on the site.
References
- https://wpsec.com/vuln/WPSEC-2026-0466/
- https://plugins.svn.wordpress.org/quiz-master-next/tags/11.2.8/
- https://wordpress.org/plugins/quiz-master-next/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS