The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 642 live websites that are affected by CVE-2026-11780.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 642 live websites (88% of Quiz Master Next install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 58 versions ( 97% of all versions) |
| 171 websites | |
| 67 websites | |
| 42 websites | |
| 34 websites | |
| 28 websites | |
| 23 websites | |
| 22 websites | |
| 21 websites | |
| 20 websites | |
| 15 websites |
| .com | 243 websites |
| .org | 37 websites |
| .ru | 33 websites |
| .de | 33 websites |
| .nl | 19 websites |
| .it | 17 websites |
| .co.uk | 14 websites |
| .fr | 13 websites |
| .pl | 12 websites |
| .com.br | 11 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******************.com | ***,*** | ||
| *************.com | ***,*** | ||
| ************.de | ***,*** | ||
| ****************.com | ***,*** | ||
| ************.org | ***,*** | ||
| ****.*******************.com | ***,*** | ||
| **************.************.***.sg | ***,*** | ||
| *********************.net | ***,*** | ||
| *******************.************.***.pl | ***,*** | ||
| ****.***.***.au | ***,*** |
FAQ