Junglewise Threat Intelligence

CVE-2026-62140: ExpressTech Quiz And Survey Master IDOR vulnerability

CVE-2026-62140 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Technologies: ExpressTech Quiz and Survey Master. Vendors: ExpressTech.

Executive brief

Quiz And Survey Master is a popular WordPress plugin for creating and managing surveys and quizzes on websites. An unauthenticated attacker can exploit an insecure direct object reference vulnerability to access and view other users' survey and quiz data by manipulating identifiers in requests, potentially exposing sensitive user information without authentication.

Technical details

An insecure direct object reference (IDOR) vulnerability exists in Quiz And Survey Master plugin versions 11.2.5 and earlier. The vulnerability allows unauthenticated attackers to access other users' quiz and survey data by directly manipulating object identifiers in URLs or API requests. No authentication is required to exploit this flaw, and the attack can be conducted remotely over the network. Successful exploitation exposes confidential survey responses and quiz results belonging to other users. The vulnerability was patched in version 11.2.6.

Affected products

  • ExpressTech Quiz And Survey Master <= 11.2.5

Timeline

  • 2026-07-21: disclosed: Vulnerability reported by Adam Kahlon (Adkali)
  • 2026-09-10: advisory: Early warning issued to Patchstack customers and published
  • 2026-09-10: patched: Fix available in version 11.2.6

References

Related threats