CVE-2026-9233: Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action

Published Jun 27, 2026
·
Updated

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create, modify, and delete quiz output templates stored in the mlwquizoutputtemplates database table, including storing unsanitized HTML content such as arbitrary script tags.

Affected Software

1 affected component
Quiz and Survey Master Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress<=11.1.4

Event History

Jun 27, 2026
CVE Published
via MITRE·06:50 AM
Data Sourced
via MITRE·06:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Sep 20, 58673
Event
via FIRST·07:02 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-9233?

The severity of CVE-2026-9233 is classified as medium with a score of 4.3.

2

How does CVE-2026-9233 affect users?

CVE-2026-9233 allows authenticated users with contributor or higher roles to bypass authorization controls and modify quizzes or surveys.

3

How do I fix CVE-2026-9233?

To fix CVE-2026-9233, update the Quiz and Survey Master plugin to version 11.1.5 or later.

4

What plugin is impacted by CVE-2026-9233?

CVE-2026-9233 affects the Quiz and Survey Master (QSM) plugin for WordPress in versions up to and including 11.1.4.

5

What is the nature of the vulnerability described in CVE-2026-9233?

CVE-2026-9233 is an authorization bypass vulnerability that allows arbitrary modifications through an AJAX action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203