CVE-2026-14821: Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14821?
CVE-2026-14821 has a risk score of 33, indicating a moderate severity vulnerability.
How do I fix CVE-2026-14821?
To fix CVE-2026-14821, update the Quiz and Survey Master plugin to version 11.1.5 or later.
Who is affected by CVE-2026-14821?
CVE-2026-14821 affects users of the Quiz and Survey Master plugin prior to version 11.1.5 with contributor-level access.
What type of vulnerability is CVE-2026-14821?
CVE-2026-14821 is an arbitrary template deletion vulnerability in the Quiz and Survey Master WordPress plugin.
Can contributor-level users exploit CVE-2026-14821?
Yes, contributor-level users can exploit CVE-2026-14821 to delete arbitrary output templates due to the lack of capability checks.