CVE-2026-97289: WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Quiz And Survey Master pluginto a version that resolves this vulnerability.Fixed in 11.2.7
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin-specific privileges. Exploitation still requires user interaction, as reflected by the UI:R attack vector.
What versions are affected?
Quiz And Survey Master versions 11.2.6 and earlier are identified as affected. The provided information does not identify a fixed version.
What is the potential impact?
Successful exploitation can allow cross-site scripting in a victim's browser. The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed.