Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
Published: 2026-07-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Quiz and Survey Master WordPress plugin, versions prior to 11.1.3, fails to enforce rate limiting or standard audit logging on its front‑end credential‑check functionality. As a result, a request to the login endpoint returns distinct responses for valid and invalid accounts. This flaw enables any internet user to enumerate valid usernames and subsequently perform password brute‑force attacks, potentially gaining unauthorized access to the plugin’s administrative interface. The weakness is an identity information disclosure, corresponding to CWE‑200.

Affected Systems

WordPress sites that use the Quiz and Survey Master plugin newer than 0.0 but older than 11.1.3, including all versions before the 11.1.3 release. The product is vendor‑agnostic but should be assumed to affect all installations of QSM where the front‑end login feature is enabled.

Risk and Exploitability

The CVSS vector for this vulnerability is 5.3, indicating medium severity. The EPSS score is 0.00224 (less than 1%), indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a simple HTTP POST to the quiz login endpoint from any external machine. No special privileges or network access are required, and the flaw does not involve code execution or privilege escalation beyond the compromised QSM admin credentials. Attacks could be automated and spread across multiple sites, but exploitation is bounded by the lack of rate limiting, which may slow but does not prevent enumeration.

Generated by OpenCVE AI on August 3, 2026 at 18:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Quiz and Survey Master plugin to version 11.1.3 or later, which implements proper rate limiting and audit logging for credential checks.
  • Configure WordPress or network firewalls to enforce IP‑based rate limiting or captcha on the QSM login endpoint if an upgrade is not immediately possible.
  • Disable the front‑end credential check or restrict access to the admin interface through plugin settings or .htaccess rules to prevent unauthenticated enumeration.

Generated by OpenCVE AI on August 3, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Quizandsurveymaster
Quizandsurveymaster quiz And Survey Master
Wordpress
Wordpress wordpress
Vendors & Products Quizandsurveymaster
Quizandsurveymaster quiz And Survey Master
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
Title Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
References

Subscriptions

Quizandsurveymaster Quiz And Survey Master
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-27T17:37:40.405Z

Reserved: 2026-07-06T08:27:15.311Z

Link: CVE-2026-14820

cve-icon Vulnrichment

Updated: 2026-07-27T17:36:45.469Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T07:16:26.083

Modified: 2026-07-27T20:33:01.673

Link: CVE-2026-14820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor