Skip to content
Threat Feed
high advisory

Stored DOM-Based XSS in Quiz and Survey Master WordPress Plugin

An unauthenticated stored XSS vulnerability in the Quiz and Survey Master plugin allows attackers to inject arbitrary web scripts by triggering a database error in the audit trail logging mechanism.

CVE search metadata

CVE search record: CVE-2026-96558. Severity: high. CVSS: 7.2. KEV: no. Product: Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (<= 11.2.6). Brief: Stored DOM-Based XSS in Quiz and Survey Master WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-qsm-xss/

The Quiz and Survey Master (QSM) - Quiz Maker & Survey Maker plugin for WordPress, in versions up to and including 11.2.6, is vulnerable to Stored DOM-Based Cross-Site Scripting (XSS). The vulnerability exists due to insufficient input sanitization and output escaping within the 'qsm_hidden_questions' parameter.

An unauthenticated attacker can exploit this by manipulating the submission process. By forcing the 'mlw_results' database insert to fail, typically by providing an oversized or duplicate 'qsm_unique_key' value, the application enters an error-handling code path. Within this specific audit trail code branch, the application writes the unescaped payload from the 'qsm_hidden_questions' parameter into the 'wp_mlw_qm_audit_trail.form_data' database table. When an administrator or user subsequently views the affected entry, the injected script executes in the context of their session, potentially leading to unauthorized actions or credential theft.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser context. This can lead to account takeover, sensitive data exfiltration, or the performance of administrative actions on behalf of the victim. Given the nature of WordPress plugins, this vulnerability affects any site running QSM versions 11.2.6 or earlier.

Recommendation

  • Patch the Quiz and Survey Master (QSM) plugin by upgrading to a version later than 11.2.6 immediately.
  • Monitor webserver access logs for anomalous POST requests to the QSM plugin endpoints, specifically looking for abnormally long 'qsm_unique_key' values or repetitive submissions targeting audit trail functionality.
  • Implement Content Security Policy (CSP) headers to mitigate the impact of potential XSS by restricting the sources from which scripts can be executed.

Immediate actions

Upgrade Quiz and Survey Master (QSM) plugin to latest version

IT Operations 48h

Mitigations

Patch QSM plugin

immediate IT Operations

CVE-2026-96558

Detection coverage 1

Detect CVE-2026-96558 Exploitation - Malicious QSM Plugin POST Request

high

Detects exploitation attempts against the QSM plugin by monitoring POST requests with suspicious or oversized parameters indicative of triggering the audit trail error path.

sigma tactics: initial_access techniques: T1059.007 sources: webserver

Detection queries are available on the platform. Get full rules →