The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Quizandsurveymaster
Quizandsurveymaster quiz And Survey Master
Wordpress
Wordpress wordpress
Vendors & Products Quizandsurveymaster
Quizandsurveymaster quiz And Survey Master
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
Title Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-19T06:00:15.994Z

Updated: 2026-08-19T13:14:55.802Z

Reserved: 2026-07-06T08:45:48.527Z

Link: CVE-2026-14826

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:33.890

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-14826

cve-icon Redhat

No data.