Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker has 75 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 75 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 9.9 out of 10. Severity breakdown: 4 critical and 13 high. 2026 was the busiest year with 23 disclosures.

The most common weakness is Cross-Site Scripting, behind 27 of the records (36%). Other recurring categories include SQL Injection, Missing Authorization.

Every one of the 75 issues recorded for Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker has a vendor fix available, so running the current release closes all known holes.

50 independent researchers contributed these findings, most of them (6) reported by Dmitrii Ignatyev. Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891010.09.2013Today16.07.20158.8Quiz And Survey Master < 4.4.4 - Multiple SQL Injections CVSS 8.8 · 16.07.201515.12.20168.8Quiz And Survey Master <= 4.7.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVSS 8.8 · 15.12.201605.03.20196.1Quiz And Survey Master <= 6.2.1 - Cross-Site Scripting CVSS 6.1 · 05.03.201913.11.20196.1Quiz And Survey Master <= 6.3.4 - Reflected Cross-Site Scripting CVSS 6.1 · 13.11.201929.07.20206.4Quiz and Survey Master <= 6.4.12 - Stored Cross-Site Scripting CVSS 6.4 · 29.07.202003.08.20208.2Quiz and Survey Master <= 7.0.0 - Unauthenticated Arbitrary File Deletion CVSS 8.2 · 03.08.20209.8Quiz and Survey Master <= 7.0.0 - Arbitrary File Upload CVSS 9.8 · 03.08.202029.08.20209.8Quiz and Survey Master <= 7.0.1 - Arbitrary File Upload CVSS 9.8 · 29.08.202026.03.20218.8Quiz And Survey Master <= 7.1.11 - Authenticated SQL injection via shortcode CVSS 8.8 · 26.03.202103.06.20216.1Quiz And Survey Master <= 7.1.17 - Reflected Cross-Site Scripting CVSS 6.1 · 03.06.20216.4Quiz And Survey Master <= 7.1.18 - Cross-Site Scripting CVSS 6.4 · 03.06.202110.08.20216.1Quiz and Survey Master <= 7.1.13 - SQL Injection CVSS 6.1 · 10.08.202113.09.20216.1Quiz and Survey Master <= 7.1.13 - Cross-Site Scripting CVSS 6.1 · 13.09.20214.8Quiz And Survey Master <= 7.3.1 - Admin+ Stored Cross-Site Scripting CVSS 4.8 · 13.09.202112.01.20228.8Quiz And Survey Master <= 7.3.6 - Cross-Site Request Forgery CVSS 8.8 · 12.01.20225.4Quiz And Survey Master <= 7.3.6 - Reflected Cross-Site Scripting CVSS 5.4 · 12.01.20225.4Quiz And Survey Master <= 7.3.6 - Stored Cross-Site Scripting CVSS 5.4 · 12.01.202229.09.20225.4Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 7.3.4 - Insecure Direct Object Reference CVSS 5.4 · 29.09.202221.10.20225.3Quiz And Survey Master <= 7.3.10 - Sensitive Information Disclosure CVSS 5.3 · 21.10.20227.2Quiz And Survey Master <= 7.3.4 - Authenticated (Administrator+) SQL Injection CVSS 7.2 · 21.10.20227.2Quiz And Survey Master <= 7.3.10 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 21.10.20226.1Quiz And Survey Master <= 7.3.4 - Reflected Cross-Site Scripting CVSS 6.1 · 21.10.20226.4Quiz And Survey Master <= 7.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 21.10.20225.4Quiz And Survey Master <= 7.3.6 - Insecure Direct Object Reference CVSS 5.4 · 21.10.20226.4Quiz And Survey Master <= 7.3.4 - Multiple Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 21.10.20224.3Quiz And Survey Master <= 7.3.10 - Missing Authorization CVSS 4.3 · 21.10.202223.10.20228.8Quiz And Survey Master <= 7.3.10 - Cross-Site Request Forgery CVSS 8.8 · 23.10.202216.11.20225.3Quiz and Survey Master <= 8.0.4 - Improper Input Validation CVSS 5.3 · 16.11.202229.11.20227.2Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer CVSS 7.2 · 29.11.202216.12.20224.3Quiz And Survey Master <= 8.0.7 - Cross-Site Request Forgery CVSS 4.3 · 16.12.202208.02.20235.4Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion CVSS 5.4 · 08.02.202315.02.20237.2Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion CVSS 7.2 · 15.02.202328.02.20234.3Quiz And Survey Master <= 8.0.10 - Cross-Site Request Forgery to Quiz Restoration CVSS 4.3 · 28.02.202316.04.20239.8Quiz and Survey Master <= 8.1.4 - Unauthenticated SQL Injection CVSS 9.8 · 16.04.202317.07.20235.3Quiz And Survey Master <= 8.1.10 - Excessive Quiz Attempts CVSS 5.3 · 17.07.20236.4Quiz And Survey Master <= 8.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Question Title CVSS 6.4 · 17.07.202312.09.20234.3Quiz And Survey Master <= 8.1.15 - Cross-Site Request Forgery via 'display_results' CVSS 4.3 · 12.09.202316.11.20236.4Quiz And Survey Master <= 8.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.11.202327.12.20234.3Quiz And Survey Master <= 8.1.18 - Cross-Site Request Forgery CVSS 4.3 · 27.12.20235.3Quiz And Survey Master <= 8.1.16 - Missing Authorization CVSS 5.3 · 27.12.202313.03.20244.4Quiz And Survey Master <= 8.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 13.03.202406.06.20249.9Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection CVSS 9.9 · 06.06.202410.06.20246.4Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 9.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 10.06.202420.06.20246.4Quiz and Survey Master <= 9.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 20.06.202413.07.20246.4Quiz and Survey Master <= 9.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 13.07.202405.08.20246.4Quiz and Survey Master (QSM) <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 05.08.202402.09.20244.4Quiz and Survey Master (QSM) <= 9.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 02.09.202411.03.20254.4Quiz and Survey Master (QSM) <= 9.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 11.03.202524.07.20254.3Quiz and Survey Master (QSM) <= 10.2.2 - Cross-Site Request Forgery to Template Creation CVSS 4.3 · 24.07.202514.08.20256.5Quiz And Survey Master <= 10.2.4 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 14.08.202503.09.20258.1Quiz And Survey Master <= 10.2.5 - Unauthenticated PHP Object Injection CVSS 8.1 · 03.09.202530.11.20255.3Quiz And Survey Master <= 10.3.2 - Missing Authorization CVSS 5.3 · 30.11.202505.01.20264.3Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion CVSS 4.3 · 05.01.20266.5Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads CVSS 6.5 · 05.01.20266.5Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter CVSS 6.5 · 05.01.202608.01.20264.3Quiz And Survey Master <= 10.3.3 - Missing Authorization CVSS 4.3 · 08.01.202628.01.20266.5Quiz And Survey Master <= 10.3.1 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 28.01.202601.02.20265.3Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 10.3.4 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 01.02.202605.02.20264.3Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 10.3.4 - Missing Authorization CVSS 4.3 · 05.02.202623.03.20266.5Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter CVSS 6.5 · 23.03.202616.04.20265.3Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields CVSS 5.3 · 16.04.202623.04.20267.2Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.0.0 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 23.04.202603.06.20267.2Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.1.2 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 03.06.202605.06.20264.9Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters CVSS 4.9 · 05.06.202626.06.20264.3Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action CVSS 4.3 · 26.06.202602.07.20264.3Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure CVSS 4.3 · 02.07.202607.07.20264.3Quiz And Survey Master <= 11.1.4 - Missing Authorization CVSS 4.3 · 07.07.202615.07.20266.5Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter CVSS 6.5 · 15.07.202622.07.20266.5Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.0 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 22.07.202627.07.20266.4Quiz And Survey Master <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 27.07.202615.08.20266.4Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter CVSS 6.4 · 15.08.20266.5Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option CVSS 6.5 · 15.08.202617.08.20264.3Quiz And Survey Master <= 11.2.3 - Authenticated (Contributor+) Insecure Direct Object Reference CVSS 4.3 · 17.08.20264.3Quiz And Survey Master <= 11.2.3 - Authenticated (Contributor+) Insecure Direct Object Reference CVSS 4.3 · 17.08.202628.08.20264.3Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker < 11.2.4 - Authenticated (Contributor+) Insecure Direct Object Reference CVSS 4.3 · 28.08.2026

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

75

Get automatic notifications for all Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2024-3592

Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection

Read the full analysis

Vulnerability Records

75 records
2026-08-28 00:00CVE-2026-79615
4.3
Medium
Shikhali JamalzadeYes
2026-08-17 00:00CVE-2026-14826
4.3
Medium
Revanth Hari Narayana MatteYes
2026-08-17 00:00CVE-2026-14825
4.3
Medium
Revanth Hari Narayana MatteYes
2026-08-15 16:20CVE-2026-15963
6.5
Medium
Wordfence PRISMYes
2026-08-15 00:00CVE-2026-11780
6.4
Medium
Jonah Burgess (CryptoCat)Yes
2026-07-27 00:00CVE-2026-14824
6.4
Medium
Meher Sudhakar AbbireddiYes
2026-07-22 00:00CVE-2026-65454
6.5
Medium
anhcd05Yes
2026-07-15 19:22CVE-2026-13767
6.5
Medium
Wordfence PRISMYes
2026-07-07 00:00CVE-2026-14821
4.3
Medium
Md. Minaruzzaman ShovonYes
2026-07-02 18:30CVE-2026-9230
4.3
Medium
alex_henry20Yes
Showing 1–10 of 75 reports
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker banner
Latestv11.2.6

Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

ExpressTech Systems

Author

ExpressTech Systems

4.7(1,281)
94/100
Last Updated
2026-09-04 (9d ago)
Active Installs
40,000+
Downloads
3,394,300
Requires WP
5.0+
Requires PHP
5.4+
Tested up to
WP 7.1
Created
2013-09-10 (13y ago)

Quiz and Survey Master (QSM) is a free quiz maker and survey maker for WordPress — trusted by 40,000+ websites and rated 4.7★ from 1,200+ reviews. QSM is the all-in-one WordPress quiz plugin for building unlimited quizzes, surveys, exams, assessments, and trivia quizzes — with a drag-and-drop builder, score-based results pages, and built-in lead capture. No code required. Whether you’re an educator scoring exams, a marketer running a lead-gen quiz, or a business gathering survey feedback, QSM gives you everything you need to build quizzes and surveys that grow with you. Live demo » · Documentation » Why QSM is the go-to WordPress quiz maker Unlimited quizzes & questions — build as many quizzes, surveys, and exams as you need, each with unlimited questions. 12+ question types — multiple choice, true/false, dropdowns, open-ended, fill-in-the-blank, file upload, captcha, and more. Drag-and-drop + Block Editor — assemble quizzes visually, or drop a quiz straight into any post or page with the QSM block. Score-based results pages — show different results, messages, or redirects for different score ranges (perfect for graded quizzes and personality tests). Flexible grading — points, percentages, and custom grading systems for exams and certifications. Fully responsive — every quiz and survey looks great on mobile, tablet, and desktop. Popular ways to use QSM Graded exams & online assessments — score answers automatically, set pass marks, and show a tailored results page. Personality & outcome quizzes — map score ranges to different results (“Which plan is right for you?”). Trivia quizzes — engage visitors and keep them on your site longer. Lead-generation quizzes — capture an email before or after the quiz and follow up automatically. Surveys, feedback forms & polls — gather customer feedback, NPS, and market research from the same builder. A complete WordPress survey maker Turn QSM into a powerful survey tool to gather feedback and market research. Build survey forms, feedback forms, and polls in minutes, share them anywhere, and analyze responses in your dashboard. Unlimited surveys and questions Custom styling, text blocks, button labels, and template variables Export and share findings across platforms Capture leads & grow your list QSM’s built-in contact form turns quiz-takers into email subscribers — capture leads before or after a quiz, then follow up automatically with custom email templates. Your quiz becomes a lead-generation engine. Reporting & analytics Track every submission with detailed quiz reporting and analytics — scores, response breakdowns, and results — so you can see exactly how people engage with your quizzes, surveys, and polls. Built for Educators and schools · training and HR teams · agencies · marketers running trivia and lead-gen quizzes · anyone who needs a free WordPress quiz or survey. Elevate your quizzes & surveys with QSM Pro Go further with QSM Pro — premium question types, advanced reporting, integrations (Mailchimp, ActiveCampaign, and more), conditional logic, certificates, and beautiful premium quiz themes. Explore QSM Pro »

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C