CVE-2026-14820
Vulnerability Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Quiz and Survey Master (QSM)
Discussion (0)
Add Comment
No comments yet. Be the first!