Impact
The Quiz and Survey Master WordPress plugin, versions prior to 11.1.3, fails to enforce rate limiting or standard audit logging on its front‑end credential‑check functionality. As a result, a request to the login endpoint returns distinct responses for valid and invalid accounts. This flaw enables any internet user to enumerate valid usernames and subsequently perform password brute‑force attacks, potentially gaining unauthorized access to the plugin’s administrative interface. The weakness is an identity information disclosure, corresponding to CWE‑200.
Affected Systems
WordPress sites that use the Quiz and Survey Master plugin newer than 0.0 but older than 11.1.3, including all versions before the 11.1.3 release. The product is vendor‑agnostic but should be assumed to affect all installations of QSM where the front‑end login feature is enabled.
Risk and Exploitability
The CVSS vector for this vulnerability is 5.3, indicating medium severity. The EPSS score is 0.00224 (less than 1%), indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a simple HTTP POST to the quiz login endpoint from any external machine. No special privileges or network access are required, and the flaw does not involve code execution or privilege escalation beyond the compromised QSM admin credentials. Attacks could be automated and spread across multiple sites, but exploitation is bounded by the lack of rate limiting, which may slow but does not prevent enumeration.
OpenCVE Enrichment