CVE-2026-5797Disclosure

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and htmlspecialchars(), which only strip HTML tags but do not encode or remove shortcode brackets [ and ]. When quiz results are displayed, the plugin calls do_shortcode() on the entire results page output (including user answers), causing any injected shortcodes to be executed. This makes it possible for unauthenticated attackers to inject arbitrary WordPress shortcodes such as [qsm_result id=X] to access other users' quiz submissions without authorization, as the qsm_result shortcode lacks any authorization checks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-17: 3PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-17: 204-17
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5797-quiz-master-next-version-10-1-0-medium-vulnerability-proof-of-concept CVE-2026-5797 #WordPress plugin #vulnerability quiz-master-next #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The tweet shares a proof‑of‑concept link for CVE-2026-5797 affecting the WordPress plugin quiz‑master‑next, noting a medium‑severity vulnerability but offering no exploit code, patch details, or evidence of active exploitation.

    0000049
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5797 The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input… https://www.cve.org/CVERecord?id=CVE-2026-5797

    Post summary

    A new CVE (CVE-2026-5797) has been disclosed for the WordPress Quiz And Survey Master plugin, enabling arbitrary shortcode execution due to insufficient input validation in versions up to 11.1.0.

    0000055
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5797 Arbitrary Shortcode Execution in Quiz And Survey Master Plugin for WordPress 11.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5797

    Post summary

    The post discloses CVE‑2026‑5797, indicating an arbitrary shortcode execution vulnerability in Quiz And Survey Master WordPress plugin version 11.1.0.

    0000034
    4.0K followersView on X

Explore more