CVE-2026-15963

Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 642 live websites that are affected by CVE-2026-15963.

Run a Free Instant Scan




Affected Software

Product  Quiz Master Next
Category Wordpress Plugins
Vulnerable Domains642 live websites (88% of Quiz Master Next install base)
Vulnerable Versions
  • from 0 through 11.2.1
Vulnerable Versions Count58 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-15963
United States171 websites



Germany67 websites
Russia42 websites
France34 websites
GB28 websites
Netherlands23 websites
Spain22 websites
Japan21 websites
Italy20 websites
Canada15 websites

Website Distribution by TLD

Number of websites using CVE-2026-15963
.com243 websites
.org37 websites
.ru33 websites
.de33 websites
.nl19 websites
.it17 websites
.co.uk14 websites
.fr13 websites
.pl12 websites
.com.br11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15963

Top websites that are affected by CVE-2026-15963. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States***,***
*************.com United States***,***
************.de Germany***,***
****************.com United States***,***
************.org United States***,***
****.*******************.com United States***,***
**************.************.***.sg United States***,***
*********************.net United States***,***
*******************.************.***.pl Poland***,***
****.***.***.au Australia***,***
See full domain list

FAQ

CVE-2026-15963 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Quiz Master Next
A total of 642 websites have been identified as vulnerable to CVE-2026-15963, based on global website indexing conducted by WebTechSurvey.
The Quiz Master Next is affected by the CVE-2026-15963 vulnerability.
Quiz Master Next versions up to and including 11.2.1 are vulnerable to CVE-2026-15963.