CVE-2026-14820: Unknown Quiz And Survey Master Qsm
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
Affected products
- Unknown Quiz And Survey Master Qsm: before 11.1.3 (fixed in 11.1.3)
Published 2026-07-27. Last modified 2026-07-27.