Back to CVE List

CVE-2026-14820

Vulnerability Description

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Quiz and Survey Master (QSM)

External References

Discussion (0)

Add Comment

No comments yet. Be the first!