Arbitrary Template Deletion in Quiz and Survey Master Plugin for WordPress
CVE-2026-14821

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 July 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-14821?

The Quiz and Survey Master plugin for WordPress, prior to version 11.1.5, lacks proper capability checks, allowing users with contributor-level access or higher to delete output templates indiscriminately. This vulnerability can lead to unauthorized modifications and significant disruptions, particularly affecting the integrity of surveys and quizzes managed through the plugin. Prompt updating of the plugin is advisable to mitigate potential risks.

Affected Version(s)

Quiz and Survey Master (QSM) 0 < 11.1.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

md. minaruzzaman shovon
WPScan
.