CVE-2026-14826

Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.


We have discovered 752 live websites that are affected by CVE-2026-14826.

Run a Free Instant Scan




Affected Software

Product  Quiz Master Next
Category Wordpress Plugins
Vulnerable Domains752 live websites (100% of Quiz Master Next install base)
Vulnerable Versions
  • from 0 through 11.2.4
Vulnerable Versions Count60 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 19, 2026
  • Updated - Aug 19, 2026

Credits

  • Revanth Hari Narayana Matte (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14826
United States209 websites



Germany85 websites
Russia45 websites
France42 websites
GB33 websites
Netherlands25 websites
Spain24 websites
Japan23 websites
Italy21 websites
Canada16 websites

Website Distribution by TLD

Number of websites using CVE-2026-14826
.com290 websites
.org45 websites
.de43 websites
.ru36 websites
.nl21 websites
.it18 websites
.co.uk16 websites
.fr15 websites
.net14 websites
.pl13 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14826

Top websites that are affected by CVE-2026-14826. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States**,***
******************.com United States***,***
*************.com United States***,***
************.de Germany***,***
****************.com United States***,***
************.org United States***,***
****.*******************.com United States***,***
*********.com United States***,***
**********.ru Russia***,***
**************.************.***.sg United States***,***
See full domain list

FAQ

CVE-2026-14826 is Authorization Bypass Through User-Controlled Key in Quiz Master Next
A total of 752 websites have been identified as vulnerable to CVE-2026-14826, based on global website indexing conducted by WebTechSurvey.
The Quiz Master Next is affected by the CVE-2026-14826 vulnerability.
Quiz Master Next versions up to 11.2.4 are vulnerable to CVE-2026-14826.
CVE-2026-14826 is resolved in version 11.2.4 of Quiz Master Next.