Search Results (6 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-14825 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-08-21 2.7 Low
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
CVE-2026-14826 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-08-21 2.7 Low
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
CVE-2025-6790 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2025-08-16 4.3 Medium
The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CVE-2021-36865 1 Quizandsurveymaster 1 Quiz And Survey Master 2025-02-20 3.8 Low
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
CVE-2023-47834 1 Quizandsurveymaster 1 Quiz And Survey Master 2024-11-21 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions.
CVE-2019-9575 1 Quizandsurveymaster 1 Quiz And Survey Master 2024-11-21 N/A
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.