Back to overview

CVE-2026-14820

Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.

Metadata

CVE ID
CVE-2026-14820
State
PUBLISHED
Assigner
WPScan
Reserved
2026-07-06 08:27 UTC
Published
2026-07-27 06:00 UTC
Last updated
2026-07-27 06:00 UTC
Vendor / Product
Unknown / Quiz and Survey Master (QSM)
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Quiz and Survey Master (QSM) 0 < 11.1.3
Weakness (CWE)
CWESourceDescription
cna CWE-200 Information Exposure
Back to overview