Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Vulnerabilities 81Slug quiz-master-nextLatest version 11.1.2WordPress.org →

Minimum safe version

11.1.1

Update to 11.1.1 or later to address 81 fixable vulnerabilities

Latest available11.1.2
N/A
2026-04-23< 11.1.0

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.0.0 - Unauthenticated Stored Cross-Site Scripting

N/A
2026-01-05< 10.3.2

Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads

N/A
2026-01-05< 10.3.2

Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter

N/A
2026-01-05< 10.3.2

Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion

N/A
2026-03-23< 11.0.0

Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter

Medium 4.3
2025-08-14< 10.2.3

Quiz and Survey Master (QSM) <= 10.2.2 - Cross-Site Request Forgery to Template Creation

Medium 5.9
2024-08-05< 9.1.0

WordPress Quiz And Survey Master Plugin < 9.1.0 is vulnerable to Cross Site Scripting (XSS)

High 8.8
2024-07-02< 9.0.2

CVE-2024-5606

N/A
< 8.1.19

Quiz And Survey Master &lt; 8.1.19 - Multiple Cross-Site Request Forgery

N/A
< 8.1.16

Quiz And Survey Master &lt; 8.1.16 - Cross-Site Request Forgery via &#039;display_results&#039;

Medium 5.3
2024-12-27< 8.1.17

WordPress Quiz And Survey Master Plugin <= 8.1.16 is vulnerable to Broken Access Control

Medium 5.4
2024-12-27< 8.1.19

WordPress Quiz And Survey Master Plugin <= 8.1.18 is vulnerable to Cross Site Request Forgery (CSRF)

N/A
2023-11-08< 8.1.19

Quiz And Survey Master <= 8.1.18 - Multiple Cross-Site Request Forgery

N/A
2023-09-13< 8.1.16

WordPress Quiz And Survey Master Plugin < 8.1.15 is vulnerable to Cross Site Request Forgery (CSRF)

N/A
2023-09-12< 8.1.16

Quiz And Survey Master <= 8.1.15 - Cross-Site Request Forgery via 'display_results'

N/A
< 4.4.4

Quiz And Survey Master &lt; 4.4.4 - Authenticated Blind SQL Injection

N/A
< 7.0.0

Quiz And Survey Master &lt; 7.0.0 - Authenticated Stored Cross-Site Scripting (XSS)

N/A
< 7.0.2

Quiz and Survey Master &lt; 7.0.2 - Unauthenticated Arbitrary File Upload

N/A
< 7.1.14

Quiz And Survey Master &lt; 7.1.14 - Authenticated SQL injection via Rest API

N/A
< 7.1.19

Quiz And Survey Master &lt; 7.1.19 - Unauthenticated Stored Cross-Site Scripting (XSS)

N/A
2023-02-28< 8.1.0

Quiz And Survey Master <= 8.0.10 - Cross-Site Request Forgery to Quiz Restoration

N/A
2015-07-16< 4.4.4

Quiz And Survey Master < 4.4.4 - Multiple SQL Injections

N/A
2020-07-29< 7.0.0

Quiz and Survey Master <= 6.4.12 - Stored Cross-Site Scripting

N/A
2020-08-29< 7.0.2

Quiz and Survey Master <= 7.0.1 - Arbitrary File Upload

N/A
2021-06-03< 7.1.19

Quiz And Survey Master <= 7.1.18 - Cross-Site Scripting

N/A
2021-08-10< 7.1.14

Quiz and Survey Master <= 7.1.13 - SQL Injection

N/A
2022-12-16< 8.0.8

Quiz And Survey Master <= 8.0.7 - Cross-Site Request Forgery

N/A
2022-10-23< 7.3.11

Quiz And Survey Master <= 7.3.10 - Cross-Site Request Forgery

N/A
< 8.0.5

WordPress Quiz And Survey Master Plugin <= 8.0.4 is vulnerable to Other Vulnerability Type

N/A
< 8.0.5

WordPress Quiz And Survey Master Plugin <= 8.0.4 is vulnerable to Other Vulnerability Type

N/A
2015-07-16< 4.4.4

WordPress Quiz And Survey Master Plugin <= 4.4.2 - Blind SQL Injection

N/A
2016-12-15< 4.7.9

WordPress Quiz And Survey Master Plugin <= 4.7.8 - Multiple Vulnerabilities

N/A
2020-08-29< 7.0.2

WordPress Quiz And Survey Master plugin <= 7.0.1 - Unauthenticated Arbitrary File Upload vulnerability

N/A
2021-03-26< 7.1.14

WordPress Quiz And Survey Master plugin <= 7.1.13 - Authenticated SQL injection (SQLi) vulnerability

N/A
2021-06-03< 7.1.19

WordPress Quiz And Survey Master plugin <= 7.1.18 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability

Medium 6.1
2019-03-12< 6.2.2

WordPress Quiz And Survey Master plugin <= 6.2.1 - Authenticated Cross-Site Scripting (XSS) vulnerability

Medium 6.1
2019-12-15< 6.3.5

WordPress Quiz And Survey Master plugin <= 6.3.4 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability