What is CVE-2026-14821?
The Quiz and Survey Master (QSM) WordPress plugin before version 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. Update the plugin to version 11.1.5 or later to mitigate this issue.
Azərbaycanca: Quiz and Survey Master (QSM) WordPress plugin-in 11.1.5-dən əvvəlki versiyalarında, çıxış şablonlarını silməzdən əvvəl capability yoxlaması aparılmır. Bu zəiflik contributor və daha yüksək səviyyəli istifadəçilərə ixtiyari şablonları silməyə imkan verir. Plugin-i ən azı 11.1.5 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Quiz and Survey Master (QSM) plugin are vulnerable to CVE-2026-14821?
All versions of the plugin before 11.1.5 are affected. Update to version 11.1.5 or later to mitigate this issue.
What level of user role is required to exploit the CVE-2026-14821 vulnerability?
At least contributor-level access is required to exploit this vulnerability. Higher roles such as author or editor are also affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.