CVE-2026-14820

Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.


We have discovered 473 live websites that are affected by CVE-2026-14820.

Run a Free Instant Scan




Affected Software

Product  Quiz Master Next
Category Wordpress Plugins
Vulnerable Domains473 live websites (71% of Quiz Master Next install base)
Vulnerable Versions
  • from 0 through 11.1.3
Vulnerable Versions Count54 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Ahmad Mubarak Alanazi (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14820
United States129 websites



Germany45 websites
Russia36 websites
France28 websites
GB22 websites
Netherlands18 websites
Spain17 websites
Japan12 websites
Poland11 websites
Italy9 websites

Website Distribution by TLD

Number of websites using CVE-2026-14820
.com179 websites
.ru28 websites
.org26 websites
.de23 websites
.nl17 websites
.co.uk10 websites
.pl9 websites
.it9 websites
.net9 websites
.fr9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14820

Top websites that are affected by CVE-2026-14820. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States***,***
*************.com United States***,***
****************.com United States***,***
****.*******************.com United States***,***
*******************.************.***.pl Poland***,***
****.***.***.au Australia***,***
*********.***.sg Singapore***,***
********.co United States***,***
*************.***.br United States***,***
**************.at Austria*,***,***
See full domain list

FAQ

CVE-2026-14820 is Exposure of Sensitive Information to an Unauthorized Actor in Quiz Master Next
A total of 473 websites have been identified as vulnerable to CVE-2026-14820, based on global website indexing conducted by WebTechSurvey.
The Quiz Master Next is affected by the CVE-2026-14820 vulnerability.
Quiz Master Next versions up to 11.1.3 are vulnerable to CVE-2026-14820.
CVE-2026-14820 is resolved in version 11.1.3 of Quiz Master Next.