Stored DOM-Based Cross-Site Scripting in Quiz and Survey Master Plugin by WordPress
CVE-2026-96558

7.2HIGH

What is CVE-2026-96558?

The Quiz and Survey Master (QSM) plugin for WordPress is susceptible to a Stored DOM-Based Cross-Site Scripting vulnerability through the 'qsm_hidden_questions' parameter in all versions up to 11.2.6. This vulnerability arises from inadequate input sanitization and output escaping. Malicious actors can exploit this weakness to inject arbitrary scripts into web pages, which execute whenever a user accesses the affected page. The exploitation involves manipulating the submission process by forcing the mlw_results INSERT to fail, thereby triggering an audit trail code that incorrectly stores the unfiltered payload in the database.

Affected Version(s)

Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker 0 <= 11.2.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.