PT-2026-64850 · WordPress · Quiz/Survey Master

CVE-2026-14820

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quiz and Survey Master (QSM) WordPress plugin versions prior to 11.1.3
Description The front-end credential-check functionality lacks rate limiting and standard failed-login auditing. Because the system returns distinct responses for valid and invalid accounts, unauthenticated attackers can enumerate valid usernames and perform brute-force password attacks while bypassing existing brute-force protections.
Recommendations Update the Quiz and Survey Master (QSM) WordPress plugin to version 11.1.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14820

Affected Products

Quiz/Survey Master