THREAT OPS › Threat News › [NVD] CVE-2026-11780 (MEDIUM 6.4) — The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes i
[NVD] CVE-2026-11780 (MEDIUM 6.4) — The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes i
CVE-2026-11780 CVSS: 6.4 MEDIUM Published: 2026-08-16T05:16:45.643
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib
Indicators of compromise
- CVE-2026-11780cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-11780