Stored DOM-Based XSS in Quiz and Survey Master WordPress Plugin
An unauthenticated stored XSS vulnerability in the Quiz and Survey Master plugin allows attackers to inject arbitrary web scripts by triggering a database error in the audit trail logging mechanism.
CVE search metadata
CVE search record: CVE-2026-96558. Severity: high. CVSS: 7.2. KEV: no. Product: Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (<= 11.2.6). Brief: Stored DOM-Based XSS in Quiz and Survey Master WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-qsm-xss/
The Quiz and Survey Master (QSM) - Quiz Maker & Survey Maker plugin for WordPress, in versions up to and including 11.2.6, is vulnerable to Stored DOM-Based Cross-Site Scripting (XSS). The vulnerability exists due to insufficient input sanitization and output escaping within the 'qsm_hidden_questions' parameter.
An unauthenticated attacker can exploit this by manipulating the submission process. By forcing the 'mlw_results' database insert to fail, typically by providing an oversized or duplicate 'qsm_unique_key' value, the application enters an error-handling code path. Within this specific audit trail code branch, the application writes the unescaped payload from the 'qsm_hidden_questions' parameter into the 'wp_mlw_qm_audit_trail.form_data' database table. When an administrator or user subsequently views the affected entry, the injected script executes in the context of their session, potentially leading to unauthorized actions or credential theft.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser context. This can lead to account takeover, sensitive data exfiltration, or the performance of administrative actions on behalf of the victim. Given the nature of WordPress plugins, this vulnerability affects any site running QSM versions 11.2.6 or earlier.
Recommendation
- Patch the Quiz and Survey Master (QSM) plugin by upgrading to a version later than 11.2.6 immediately.
- Monitor webserver access logs for anomalous POST requests to the QSM plugin endpoints, specifically looking for abnormally long 'qsm_unique_key' values or repetitive submissions targeting audit trail functionality.
- Implement Content Security Policy (CSP) headers to mitigate the impact of potential XSS by restricting the sources from which scripts can be executed.
Immediate actions
Upgrade Quiz and Survey Master (QSM) plugin to latest version
Mitigations
Patch QSM plugin
CVE-2026-96558
Detection coverage 1
Detect CVE-2026-96558 Exploitation - Malicious QSM Plugin POST Request
highDetects exploitation attempts against the QSM plugin by monitoring POST requests with suspicious or oversized parameters indicative of triggering the audit trail error path.
Detection queries are available on the platform. Get full rules →