Quiz and Survey Master Unauthorized Access and Data Modification Vulnerability (CVE-2025-9637) — Medium Severity

A significant security flaw has been found in the Quiz and Survey Master (QSM) plugin for WordPress. This vulnerability, identified as CVE-2025-9637, could allow malicious actors to gain unauthorized access to private quiz information and even upload files without proper permission. This is a concern for website administrators and anyone using the QSM plugin to manage quizzes and surveys on their WordPress sites.

The core issue stems from missing security checks within the plugin. Specifically, several functions lack the necessary capability and status checks. This oversight means that even someone who isn’t logged in or authorized could potentially view details of quizzes meant to be private, unpublished, or protected by a password. Furthermore, if these quizzes include questions that allow file uploads, an attacker could exploit this to submit files to your server without authentication.

CVE Details

  • Product: Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress
  • Published: January 6, 2026
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts the Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress. All versions up to, and including, 10.3.1 are susceptible to this flaw. If you are running any version within this range, your WordPress site could be at risk.

Current Status

The status of this vulnerability is currently “Analyzed.” This means that the details of the flaw have been thoroughly investigated and confirmed by security researchers. While the vulnerability is understood, immediate action is required from users to protect their websites.

Severity Level

This vulnerability carries a “Medium” severity rating, with a CVSS score of 6.5. This rating reflects the potential for significant impact, even though it might not always lead to immediate full system compromise. The ability for unauthenticated users to view private content and upload potentially harmful files can lead to data breaches, website defacement, or other security incidents. It’s crucial to address this promptly to maintain the integrity and privacy of your quiz and survey data.

Possible Solutions

The most important step you can take to protect your WordPress site from CVE-2025-9637 is to update the Quiz and Survey Master plugin immediately. Ensure you update to a version beyond 10.3.1, as newer versions are expected to include the necessary security patches addressing these missing capability and status checks. Always back up your website before performing any plugin updates.

Regularly updating all your WordPress themes and plugins is a fundamental security best practice. Staying current with software versions ensures you receive the latest security fixes and helps safeguard your website against known vulnerabilities.

References

https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/classes/class-qmn-quiz-manager.php#L1987

https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/classes/class-qmn-quiz-manager.php#L281

https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/rest-api.php

https://www.wordfence.com/threat-intel/vulnerabilities/id/88a9abf4-62a9-4695-87e7-18ff0b0075e9?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.