What is CVE-2026-14824?
This vulnerability exists in the Quiz and Survey Master (QSM) WordPress plugin before version 11.2.2. Due to improper escaping of a question parameter into an unquoted HTML attribute, a user with contributor-level access can inject arbitrary JavaScript, executing in the browsers of anyone viewing the quiz. Users must immediately update the plugin to the latest version.
Azərbaycanca: Bu boşluq Quiz and Survey Master (QSM) WordPress plaginin 11.2.2-dən əvvəlki versiyalarında aşkar edilib. Sualların parametrlərini düzgün escapə etməməsi səbəbindən, contributor səviyyəsində girişi olan istifadəçi istənilən JavaScript kodunu yeridə bilər ki, bu da sorğuya baxan digər istifadəçilərin brauzerində icra olunur. Plagintən dərhal son versiyaya yeniləməlisiniz.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Quiz and Survey Master plugin are affected by CVE-2026-14824?
This vulnerability exists in versions of the plugin before 11.2.2.
What level of access is required to exploit this vulnerability?
A user with contributor-level access can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.