Quiz and Survey Master (QSM) WordPress 插件在 11.2.4 版本之前,通过其 REST API 路由返回题库条目时未进行权限检查,导致角色低到“投稿者”的用户也能读取其他用户的测验题目、提示及正确答案选项。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Quiz and Survey Master (QSM) | < 11.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Quiz and Survey Master (QSM) | 0 ~ 11.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79996 | User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Sett | |
| CVE-2026-77701 | WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders | |
| CVE-2026-19423 | Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Pr | |
| CVE-2026-79706 | Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal | |
| CVE-2026-79995 | User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via | |
| CVE-2026-19084 | Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read | |
| CVE-2026-14567 | WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Direc | |
| CVE-2026-14558 | WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder | |
| CVE-2026-12514 | Shared Files < 1.7.70 - Unauthenticated Limited File Upload | |
| CVE-2026-12513 | Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal |
No comments yet