CVE-2026-62140: WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
Affected Software
1 affected component
WordPress Quiz And Survey Master<=11.2.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Quiz And Survey Master pluginto a version that resolves this vulnerability.Fixed in 11.2.6
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to exploit it.
2
What is the potential impact?
The supplied severity vector indicates network-reachable exploitation with low attack complexity and low confidentiality impact. No integrity or availability impact is indicated.
3
Which plugin versions are affected?
Quiz And Survey Master versions 11.2.5 and earlier are identified as affected.