CVE-2026-79615 PUBLISHED

Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR

Assigner: WPScan
Reserved: 25.08.2026 Published: 28.08.2026 Updated: 28.08.2026

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.

Product Status

Vendor Unknown
Product Quiz and Survey Master (QSM)
Versions Default: unaffected
  • affected from 0 to 11.2.4 (excl.)

Credits

  • Shikhali Jamalzade finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE