CyberRota Analysis
AI-GeneratedThe Quiz and Survey Master plugin for WordPress prior to version 11.1.3 is vulnerable due to the lack of rate limiting and failed-login auditing, which allows unauthenticated attackers to enumerate valid usernames and perform brute-force password attacks. This could lead to unauthorized access to user accounts, compromising the security of the WordPress site. Site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.