Description
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data exposure via IDOR
Action: Patch
AI Analysis

Impact

The vulnerability is an insecure direct object reference that allows unauthenticated users to request arbitrary survey or quiz data by manipulating URLs or identifiers. This weak access control can lead to disclosure of other users’ responses or survey contents, but it does not provide code execution or higher‑level attacks. The weakness corresponds to CWE‑639. The CVSS score is 5.3, indicating moderate severity, while the EPSS score of < 1% shows a very low but nonzero chance of exploitation.

Affected Systems

ExpressTech Systems’ WordPress plugin Quiz And Survey Master, versions up to and including 11.2.5. Any site running these versions is vulnerable or later.

Risk and Exploitability

Risk analysis indicates a CVSS score of 5.3, reflecting moderate impact. The EPSS score of < 1% suggests an extremely low but nonzero probability of exploitation. The vulnerability is not in CISA’s KEV catalog. Because the flaw permits unauthenticated access to survey data, an attacker can read responses or survey structures without needing privileged credentials, but cannot execute code or modify site configuration. The web-based attack vector relies on manipulating URLs or identifiers within the plugin.

Generated by OpenCVE AI on September 21, 2026 at 04:34 UTC.

Remediation

Vendor Solution

Update the WordPress Quiz And Survey Master Plugin to the latest available version (at least 11.2.6).


OpenCVE Recommended Actions

  • Update the plugin to version 11.2.6 or later.
  • Verify that the update implements proper access control to restrict survey data to authorized users.
  • Apply general WordPress hardening: restrict direct access to plugin URLs or files, enable role‑based restrictions, and monitor for unauthorized access attempts.

Generated by OpenCVE AI on September 21, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Expresstech
Expresstech quiz And Survey Master
Wordpress
Wordpress wordpress
Vendors & Products Expresstech
Expresstech quiz And Survey Master
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
Title WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Expresstech Quiz And Survey Master
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T20:19:11.936Z

Reserved: 2026-07-13T06:15:23.737Z

Link: CVE-2026-62140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:45.523

Modified: 2026-09-11T21:17:13.017

Link: CVE-2026-62140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key