CVE-2026-9233Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create, modify, and delete quiz output templates stored in the mlw_quiz_output_templates database table, including storing unsanitized HTML content such as arbitrary script tags.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-27: 3Technical Details · 2026-06-27: 306-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9233 Authorization Bypass in Quiz and Survey Master WordPress Plugin Up to 11.1.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9233

    Post summary

    A newly identified CVE-2026-9233 reveals an authorization bypass in the Quiz and Survey Master WordPress Plugin (versions up to 11.1.4), as reported on Vulmon.

    00030144
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9233 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. T… https://www.cve.org/CVERecord?id=CVE-2026-9233 ----- Traducción: CVE-2026-9233 The… http://infoflow.cloud`

    Post summary

    The post discloses CVE-2026-9233, identifying an authorization bypass in the WordPress Quiz and Survey Master plugin, with no indication of exploits, active attacks, or patches.

    0001035
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9233 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. T… https://www.cve.org/CVERecord?id=CVE-2026-9233

    Post summary

    CVE‑2026‑9233 is an authorization bypass vulnerability affecting all Quiz and Survey Master WordPress plugin versions up to 11.1.4, with no PoC, exploit code, or patch details provided in the text.

    00010722
    57.7K followersView on X

Explore more