CVE-2026-14820
Received Received - Intake

Username Enumeration and Brute Force in Quiz and Survey Master WordPress Plugin

Vulnerability report for CVE-2026-14820, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: WPScan

Description

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quiz_and_survey_master qsm to 11.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14820 affects the Quiz and Survey Master (QSM) WordPress plugin before version 11.1.3. It allows unauthenticated attackers to enumerate valid usernames and brute-force passwords due to missing rate limiting and failed-login auditing. The plugin returns distinct responses for valid and invalid accounts, enabling attackers to bypass brute-force protection.

Detection Guidance

To detect this vulnerability, monitor WordPress login attempts for the Quiz and Survey Master plugin. Check for repeated failed login attempts with distinct error messages for valid and invalid usernames. Use tools like WPScan to identify if the plugin version is below 11.1.3.

Impact Analysis

If you use the vulnerable QSM plugin, attackers could exploit this to guess valid usernames and passwords, potentially gaining unauthorized access to your WordPress site. This could lead to data theft, defacement, or further compromise of your site or users.

Compliance Impact

This vulnerability could lead to unauthorized access, potentially exposing sensitive user data. This may violate GDPR (data protection) and HIPAA (health data privacy) requirements, depending on the data processed by the plugin. Non-compliance risks fines and legal consequences.

Mitigation Strategies

Immediately update the Quiz and Survey Master plugin to version 11.1.3 or later. Implement rate limiting and failed-login logging on the front-end login functionality. Disable or restrict access to the credential-check endpoint if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14820. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart