Sceawere

Vulnerability Detail

CVE-2026-14825UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Quiz and Survey Master Insecure Direct Object Reference

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
11h ago
Vendor
Unknown
Product
Quiz and Survey Master (QSM)
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-08-19T06:17:33.610Z",
  "pubdate": "2026-08-19T06:17:33.610Z",
  "executiveSummary": "An Insecure Direct Object Reference vulnerability exists in the Quiz and Survey Master (QSM) WordPress plugin prior to version 11.2.4.\nThe flaw stems from an absent per-object ownership validation check when saving front-end text settings for quizzes.\nThis security deficiency allows authenticated malicious actors with contributor-level privileges or higher to modify the configuration settings of quizzes authored by other users.\nThe primary risk involves unauthorized tampering with quiz front-end content, potentially leading to defacement, social engineering attacks, or disruption of assessment integrity across the WordPress site.\nExploitation requires low privileges, specifically an authenticated account with contributor access, and network access to the target WordPress instance.\nNo complex user interaction is mandated to successfully execute the modification of arbitrary quiz objects within the affected component.",
  "technicalDetails": "The root cause of the vulnerability resides in the access control implementation of the Quiz and Survey Master (QSM) WordPress plugin.\nSpecifically, the application fails to enforce rigorous per-object ownership checks before processing requests to save front-end text settings for specific quizzes.\nWhile the request may originate from an authenticated session, the authorization logic validates only general role-based permissions rather than verifying whether the requesting user owns or holds legitimate administrative control over the targeted quiz object.\nThe vulnerable component handles state-changing requests related to quiz configuration parameters.\nAn attacker possessing contributor-level privileges can leverage this authorization flaw to target quizzes created by administrators or other higher-privileged users.\nThe step-by-step attack flow begins with the attacker identifying a target quiz ID created by a different user.\nThe attacker then crafts a forged request or intercepts a legitimate save request targeting the front-end text settings.\nBy substituting the quiz identifier with the target victim's quiz ID, the attacker bypasses logical boundaries due to the missing ownership validation.\nThe backend handler processes the modification request and updates the database with the attacker-supplied front-end text settings for the arbitrary quiz object.\nThe affected versions include all releases of the Quiz and Survey Master (QSM) WordPress plugin prior to version 11.2.4.\nThe network exposure is standard for web-based WordPress plugins, requiring network access via HTTP or HTTPS to the administrative or front-end interface endpoints exposed by the plugin.\nThe post-exploitation impact includes unauthorized alteration of quiz messaging, potential injection of malicious scripts if input sanitization is insufficient within the text fields, and disruption of data integrity for organizational assessments."
}
CVE-2026-14825: Quiz and Survey Master Insecure Direct Object Reference (LOW Severity, CVSS: 2.7) - Sceawere