Authorization Flaw in Quiz and Survey Master Plugin by WordPress
CVE-2026-14826
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14826?
The Quiz and Survey Master plugin for WordPress prior to version 11.2.4 has a significant authorization issue in its REST routes. Users with contributor-level access and above can access sensitive configuration data for quizzes created by other users, including email notification recipient addresses and results-page settings. This flaw compromises user privacy and quiz integrity, highlighting the importance of robust ownership verification mechanisms in plugin development.
Affected Version(s)
Quiz and Survey Master (QSM) 0 < 11.2.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.