What is CVE-2026-15963?
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to generic SQL Injection via the 'randon_category' Quiz Option in all versions up to and including 11.2.1. This is caused by insufficient escaping of user-supplied parameters and lack of proper query preparation. It is recommended to update the plugin to the latest version immediately.
Azərbaycanca: WordPress üçün nəzərdə tutulmuş "Quiz and Survey Master" (QSM) plaqininin 11.2.1-ə qədər olan bütün versiyaları 'randon_category' Quiz Seçimi vasitəsilə generic SQL Injection zəifliyinə məruz qalıb. Bu boşluq istifadəçi tərəfindən təqdim edilən parametrin kifayət qədər təmizlənməməsi və sorğunun düzgün hazırlanmaması səbəbindən yaranır. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What vulnerability was discovered in the Quiz and Survey Master plugin and what causes it?
A generic SQL Injection vulnerability was discovered in the QSM plugin up to version 11.2.1 via the 'randon_category' Quiz Option. It is caused by insufficient escaping of user-supplied parameters and lack of proper query preparation.
What should be done to protect against this vulnerability?
To protect against this vulnerability, it is recommended to update the Quiz and Survey Master plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.