What is CVE-2026-14825?
A vulnerability identified as CVE-2026-14825 exists in the Quiz and Survey Master (QSM) WordPress plugin before version 11.2.4. The plugin fails to perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. Upgrade to version 11.2.4 or later immediately to mitigate this issue.
Azərbaycanca: Quiz and Survey Master (QSM) WordPress plaginində CVE-2026-14825 zəifliyi aşkar edilib. Plagin 11.2.4 versiyasından əvvəl 'per-object ownership check' etmədiyi üçün, contributor və yuxarı səviyyəli istifadəçilər başqa istifadəçilərin viktorinalarının ön üz mətn parametrlərini dəyişə bilərlər. Təsirə məruz qalmamaq üçün plaqini dərhal 11.2.4 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the QSM plugin are affected by CVE-2026-14825?
The vulnerability affects all versions of the Quiz and Survey Master plugin prior to version 11.2.4.
What minimum user role is required to exploit CVE-2026-14825?
An attacker needs at least a contributor-level user role to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.