Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
Published:
2026-08-28
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 28 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. | |
| Title | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-28T06:00:17.000Z
Reserved: 2026-08-25T07:42:25.726Z
Link: CVE-2026-79615
No data.
Status : Received
Published: 2026-08-28T08:16:42.150
Modified: 2026-08-28T08:16:42.150
Link: CVE-2026-79615
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.