{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/quiz-and-survey-master-qsm--quiz-maker--survey-maker--11.2.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quiz_and_survey_master_project:quiz_and_survey_master:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96558"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quiz and Survey Master (QSM) – Quiz Maker \u0026 Survey Maker (\u003c= 11.2.6)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Quiz and Survey Master (QSM) - Quiz Maker \u0026amp; Survey Maker plugin for WordPress, in versions up to and including 11.2.6, is vulnerable to Stored DOM-Based Cross-Site Scripting (XSS). The vulnerability exists due to insufficient input sanitization and output escaping within the 'qsm_hidden_questions' parameter.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can exploit this by manipulating the submission process. By forcing the 'mlw_results' database insert to fail, typically by providing an oversized or duplicate 'qsm_unique_key' value, the application enters an error-handling code path. Within this specific audit trail code branch, the application writes the unescaped payload from the 'qsm_hidden_questions' parameter into the 'wp_mlw_qm_audit_trail.form_data' database table. When an administrator or user subsequently views the affected entry, the injected script executes in the context of their session, potentially leading to unauthorized actions or credential theft.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser context. This can lead to account takeover, sensitive data exfiltration, or the performance of administrative actions on behalf of the victim. Given the nature of WordPress plugins, this vulnerability affects any site running QSM versions 11.2.6 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the Quiz and Survey Master (QSM) plugin by upgrading to a version later than 11.2.6 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous POST requests to the QSM plugin endpoints, specifically looking for abnormally long 'qsm_unique_key' values or repetitive submissions targeting audit trail functionality.\u003c/li\u003e\n\u003cli\u003eImplement Content Security Policy (CSP) headers to mitigate the impact of potential XSS by restricting the sources from which scripts can be executed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:52:55Z","date_published":"2026-10-10T07:52:55Z","id":"https://feed.craftedsignal.io/briefs/2026-10-qsm-xss/","summary":"An unauthenticated stored XSS vulnerability in the Quiz and Survey Master plugin allows attackers to inject arbitrary web scripts by triggering a database error in the audit trail logging mechanism.","title":"Stored DOM-Based XSS in Quiz and Survey Master WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-qsm-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Quiz and Survey Master (QSM) – Quiz Maker \u0026 Survey Maker (\u003c= 11.2.6)","version":"https://jsonfeed.org/version/1.1"}