Stored DOM-Based Cross-Site Scripting in Quiz and Survey Master Plugin by WordPress
CVE-2026-96558
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-96558?
The Quiz and Survey Master (QSM) plugin for WordPress is susceptible to a Stored DOM-Based Cross-Site Scripting vulnerability through the 'qsm_hidden_questions' parameter in all versions up to 11.2.6. This vulnerability arises from inadequate input sanitization and output escaping. Malicious actors can exploit this weakness to inject arbitrary scripts into web pages, which execute whenever a user accesses the affected page. The exploitation involves manipulating the submission process by forcing the mlw_results INSERT to fail, thereby triggering an audit trail code that incorrectly stores the unfiltered payload in the database.
Affected Version(s)
Quiz and Survey Master (QSM) β Quiz Maker & Survey Maker 0 <= 11.2.6