Executive brief
The Quiz and Survey Master plugin for WordPress, which is used to create and manage online quizzes and surveys, contains a security flaw in how it handles template management. This vulnerability allows users with low-level 'Contributor' accounts to delete quiz output templates that they should not have access to. An exploit could lead to the loss of customized quiz layouts and disruption of survey operations, though it does not directly expose sensitive customer data.
Technical details
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to an authorization bypass (Missing Authorization) in its template deletion functionality. The 'qsm_remove_my_templates' AJAX action fails to implement proper capability checks or ownership verification. An attacker with Contributor-level privileges can obtain a valid nonce from the quiz emails tab and then send a crafted request to wp-admin/admin-ajax.php to delete arbitrary template IDs. This issue is fixed in version 11.1.5.
Affected products
- Unknown Quiz and Survey Master (QSM) before 11.1.5
Timeline
- 2026-07-07: disclosed
- 2026-07-28: advisory: NVD publication date