SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-79615

LOW · CVSS 2.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Quiz and Survey Master plugin for WordPress prior to version 11.2.4 is vulnerable due to insufficient authorization checks in its REST API, enabling users with a Contributor role to access sensitive quiz data, including questions and correct answers, belonging to other users. This exposure could lead to unauthorized information disclosure, potentially compromising quiz integrity and user privacy. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data leakage.

CVE
CVE-2026-79615
Severity
LOW
CVSS
2.7
EPSS
0.22%
WordPress

Original NVD Description

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.