CVE-2026-14820: Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14820?
CVE-2026-14820 has a risk score of 52, indicating a moderate level of severity.
How do I fix CVE-2026-14820?
To fix CVE-2026-14820, update the Quiz and Survey Master plugin to version 11.1.3 or later.
What type of vulnerability is CVE-2026-14820?
CVE-2026-14820 is an unauthenticated user enumeration and password oracle vulnerability.
Who is affected by CVE-2026-14820?
Users of the Quiz and Survey Master WordPress plugin versions prior to 11.1.3 are affected by CVE-2026-14820.
What exploit does CVE-2026-14820 allow?
CVE-2026-14820 allows unauthenticated attackers to enumerate valid usernames through distinct responses to login attempts.