What is CVE-2026-11780?
CVE-2026-11780 is a Stored Cross-Site Scripting vulnerability in the Quiz and Survey Master (QSM) plugin for WordPress. Insufficient sanitization of the 'question_title' parameter allows authenticated users to inject malicious scripts. Users should update the plugin to the latest patched version.
Azərbaycanca: CVE-2026-11780 WordPress üçün "Quiz and Survey Master (QSM)" pluginində aşkarlanmış Stored XSS zəifliyidir. 'question_title' parametrindəki düzgün təmizləmə çatışmazlığı autentifikasiyalı istifadəçilərə zərərli skript yerləşdirməyə imkan verir. Pluguini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What platform is affected by CVE-2026-11780?
This vulnerability was found in the Quiz and Survey Master (QSM) plugin for WordPress.
Is authentication required to exploit CVE-2026-11780?
Yes, this Stored XSS vulnerability can be exploited by authenticated users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.