A significant security flaw has been found in the Quiz and Survey Master (QSM) plugin for WordPress. This vulnerability, identified as CVE-2025-9637, could allow malicious actors to gain unauthorized access to private quiz information and even upload files without proper permission. This is a concern for website administrators and anyone using the QSM plugin to manage quizzes and surveys on their WordPress sites.
The core issue stems from missing security checks within the plugin. Specifically, several functions lack the necessary capability and status checks. This oversight means that even someone who isn’t logged in or authorized could potentially view details of quizzes meant to be private, unpublished, or protected by a password. Furthermore, if these quizzes include questions that allow file uploads, an attacker could exploit this to submit files to your server without authentication.
CVE Details
- Product: Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress
- Published: January 6, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts the Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress. All versions up to, and including, 10.3.1 are susceptible to this flaw. If you are running any version within this range, your WordPress site could be at risk.
Current Status
The status of this vulnerability is currently “Analyzed.” This means that the details of the flaw have been thoroughly investigated and confirmed by security researchers. While the vulnerability is understood, immediate action is required from users to protect their websites.
Severity Level
This vulnerability carries a “Medium” severity rating, with a CVSS score of 6.5. This rating reflects the potential for significant impact, even though it might not always lead to immediate full system compromise. The ability for unauthenticated users to view private content and upload potentially harmful files can lead to data breaches, website defacement, or other security incidents. It’s crucial to address this promptly to maintain the integrity and privacy of your quiz and survey data.
Possible Solutions
The most important step you can take to protect your WordPress site from CVE-2025-9637 is to update the Quiz and Survey Master plugin immediately. Ensure you update to a version beyond 10.3.1, as newer versions are expected to include the necessary security patches addressing these missing capability and status checks. Always back up your website before performing any plugin updates.
Regularly updating all your WordPress themes and plugins is a fundamental security best practice. Staying current with software versions ensures you receive the latest security fixes and helps safeguard your website against known vulnerabilities.
References
https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/classes/class-qmn-quiz-manager.php#L1987
https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/classes/class-qmn-quiz-manager.php#L281
https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/rest-api.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/88a9abf4-62a9-4695-87e7-18ff0b0075e9?source=cve


