CVE-2026-79615: Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user with at least the Contributor role can exploit the affected REST API route. The attacker does not need ownership of the target quiz.
What information can be exposed?
An attacker can read question bank entries for quizzes owned by other users, including questions, hints, and correct answer keys.
Are sites affected if they do not allow Contributor accounts?
The described attack requires an authenticated user with a role as low as Contributor. The provided information does not establish whether lower-privileged roles or unauthenticated visitors can access the affected route.
What version addresses the issue?
Upgrade Quiz and Survey Master to version 11.2.4 or later. Versions before 11.2.4 are affected.