CVE detail
CVE-2026-11780
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 11
- within the 30d window
- Peak daily
- 11
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/66334c29-c9d6-48b0-8d6b-bae588da0331?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3612474%40quiz-master-next&new=3612474%40quiz-master-nextplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3609172%40quiz-master-next&new=3609172%40quiz-master-nextplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.4/php/rest-api.php#L741plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.4/php/rest-api.php#L301plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.4/php/admin/options-page-questions-tab.php#L1580plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.4/php/admin/options-page-questions-tab.php#L1557plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.0.0/php/rest-api.php#L741plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.0.0/php/rest-api.php#L301plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.0.0/php/admin/options-page-questions-tab.php#L1580plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.0.0/php/admin/options-page-questions-tab.php#L1557plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-74999CVSS 5.4 · Medium
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
- CVE-2026-74998CVSS 7.2 · High
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or…
- CVE-2026-40126CVSS 4.8 · Medium
OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicio…
- CVE-2026-74800CVSS 9.4 · Critical
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenti…
- CVE-2026-19998CVSS 2.1 · Low
A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument em…
- CVE-2026-19995CVSS 2.0 · Low
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. Thi…