Authorization Bypass in Quiz and Survey Master Plugin for WordPress
CVE-2026-9233

4.3MEDIUM

What is CVE-2026-9233?

The Quiz and Survey Master plugin for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access and above to bypass authorization controls. This flaw enables them to create, modify, and delete quiz output templates stored in the mlw_quiz_output_templates database table. The vulnerability arises because the plugin fails to adequately verify user permissions, potentially allowing the insertion of unsanitized HTML content, including arbitrary script tags, posing a significant security risk.

Affected Version(s)

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker 0 <= 11.1.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Weerawat Pawanawiwat (ErbaZZ)
.