What is CVE-2026-14820?
This vulnerability allows unauthenticated attackers to enumerate valid user accounts through distinct responses returned by the front-end credential check functionality due to missing rate limiting and failed-login auditing. Affecting Quiz and Survey Master WordPress plugin versions prior to 11.1.3, the immediate action is to update the plugin to the latest version.
Azərbaycanca: Bu zəiflik, autentifikasiya olunmamış hücumçulara front-end giriş yoxlaması zamanı alınan fərqli cavablar vasitəsilə sistemdəki etibarlı istifadəçi hesablarını müəyyən etməyə imkan verir. Rate limiting və standart uğursuz giriş auditinin olmaması səbəbindən, QSM WordPress plugin-inin 11.1.3-dən əvvəlki versiyaları təsirlənir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of attack can be carried out using CVE-2026-14820?
This vulnerability allows unauthenticated attackers to enumerate valid user accounts on the system.
How can CVE-2026-14820 be mitigated?
The immediate action is to update the affected Quiz and Survey Master WordPress plugin to the latest version (11.1.3 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.