Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
CVE-2026-14820
Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
Affected products
1- Range: <11.1.3
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/22af8c73-8147-4205-8285-a35881f2d041/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.