CVE-2026-14820: Unknown Quiz And Survey Master Qsm

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.

Affected products

  • Unknown Quiz And Survey Master Qsm: before 11.1.3 (fixed in 11.1.3)

Published 2026-07-27. Last modified 2026-07-27.