CVE-2025-9294Medium· 4.3▾ SunlitThe Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and includ…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete quiz results.
quiz_and_survey_master < 10.3.2Upgrade past the affected range:
quiz_and_survey_master 10.3.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-9637Medium· 6.5The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, a…
CVE-2025-9318Medium· 6.5The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the …
CVE-2026-61837Medium· 6.3RabbitMQ is a messaging and streaming broker
CVE-2026-61604Critical· 9.3The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet
CVE-2026-63330High· 7.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-56828High· 8.8Shopper: privilege escalation via improper Livewire admin component authorization