GHSA-p22c-6jvf-q7g6LowCVSS 2.7

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.

🔗 References (3)