Executive brief
The Quiz and Survey Master plugin for WordPress, used for creating interactive quizzes and surveys, contains a security flaw that allows unauthorized users to modify content. An attacker with a basic contributor account can change quizzes they do not own, alter results pages, and redirect notification emails to their own addresses. This could lead to the disruption of survey operations and the unauthorized interception of participant data.
Technical details
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to a missing authorization check (CWE-862) in all versions up to and including 11.1.4. The vulnerability exists because the plugin fails to verify quiz ownership when processing requests to certain REST API endpoints. An authenticated attacker with contributor-level permissions can exploit this by first calling the /quiz/structure endpoint with a victim's quiz ID to obtain a valid nonce. By presenting this nonce to the /quizzes/{id}/emails save endpoint, the attacker can bypass ownership checks to modify quiz structures, overwrite results pages, or change notification email recipients.
Affected products
- ExpressTech Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.1.4
Timeline
- 2026-07-03: disclosed: CVE published to the NVD dataset
References
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/blocks/block.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/blocks/block.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/mlw_quizmaster2.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/php/rest-api.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/php/rest-api.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/php/rest-api.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/blocks/block.php