The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
We have discovered 473 live websites that are affected by CVE-2026-14820.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 473 live websites (71% of Quiz Master Next install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 54 versions ( 93% of all versions) |
| 129 websites | |
| 45 websites | |
| 36 websites | |
| 28 websites | |
| 22 websites | |
| 18 websites | |
| 17 websites | |
| 12 websites | |
| 11 websites | |
| 9 websites |
| .com | 179 websites |
| .ru | 28 websites |
| .org | 26 websites |
| .de | 23 websites |
| .nl | 17 websites |
| .co.uk | 10 websites |
| .pl | 9 websites |
| .it | 9 websites |
| .net | 9 websites |
| .fr | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******************.com | ***,*** | ||
| *************.com | ***,*** | ||
| ****************.com | ***,*** | ||
| ****.*******************.com | ***,*** | ||
| *******************.************.***.pl | ***,*** | ||
| ****.***.***.au | ***,*** | ||
| *********.***.sg | ***,*** | ||
| ********.co | ***,*** | ||
| *************.***.br | ***,*** | ||
| **************.at | *,***,*** |
FAQ