SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14820

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Quiz and Survey Master plugin for WordPress prior to version 11.1.3 is vulnerable due to the lack of rate limiting and failed-login auditing, which allows unauthenticated attackers to enumerate valid usernames and perform brute-force password attacks. This could lead to unauthorized access to user accounts, compromising the security of the WordPress site. Site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14820
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.