CVE-2026-9233: Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create, modify, and delete quiz output templates stored in the mlwquizoutputtemplates database table, including storing unsanitized HTML content such as arbitrary script tags.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9233?
The severity of CVE-2026-9233 is classified as medium with a score of 4.3.
How does CVE-2026-9233 affect users?
CVE-2026-9233 allows authenticated users with contributor or higher roles to bypass authorization controls and modify quizzes or surveys.
How do I fix CVE-2026-9233?
To fix CVE-2026-9233, update the Quiz and Survey Master plugin to version 11.1.5 or later.
What plugin is impacted by CVE-2026-9233?
CVE-2026-9233 affects the Quiz and Survey Master (QSM) plugin for WordPress in versions up to and including 11.1.4.
What is the nature of the vulnerability described in CVE-2026-9233?
CVE-2026-9233 is an authorization bypass vulnerability that allows arbitrary modifications through an AJAX action.