What is CVE-2026-14826?
CVE-2026-14826 affects the Quiz and Survey Master (QSM) WordPress plugin before version 11.2.4. It fails to perform object ownership checks on REST routes, allowing users with Contributor access or higher to read sensitive configurations like email notifications and results pages. Immediate update to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-14826 QSM WordPress plugin-inin 11.2.4-dən əvvəlki versiyalarında aşkar edilib. Plugin REST API üzərindən obyekt sahibliyi yoxlaması (per-object ownership check) aparmır, bu səbəbdən Contributor səviyyəsindən yuxarı olan istifadəçilər email bildirişləri və nəticə səhifəsi konfiqurasiyaları daxil olmaqla həssas məlumatları oxuya bilirlər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the QSM plugin are affected by CVE-2026-14826?
CVE-2026-14826 affects the Quiz and Survey Master (QSM) WordPress plugin before version 11.2.4.
What sensitive information can a user exploiting this vulnerability access?
Users can read sensitive information including email notifications and results page configurations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.