Understanding the Vulnerability
The Quiz and Survey Master (QSM) plugin for WordPress, a popular tool for creating interactive quizzes and surveys, has been found to have a security flaw. This vulnerability could lead to unauthorized deletion of important data, specifically quiz results. The issue stems from a missing security check in a function responsible for deleting results, allowing users with even basic subscriber-level access to remove data they shouldn’t be able to touch.
CVE Details
Product: Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress
Published: January 6, 2026
Severity: Medium
Status: Analyzed
Affected Products
This vulnerability affects all versions of the Quiz and Survey Master (QSM) plugin for WordPress up to, and including, version 10.3.1. If you are running any version within this range, your site could be at risk.
Current Status
The vulnerability, identified as CVE-2025-9294, has been analyzed. This means the details of the flaw are understood and documented. Users should stay vigilant for updates from the plugin developers.
Severity Level
Rated as Medium severity with a CVSS score of 4.3, this vulnerability, while not allowing for full site compromise, poses a significant risk to data integrity. Unauthorized deletion of quiz results can disrupt data analysis, reporting, and overall functionality for site administrators and owners who rely on this information.
Possible Solutions
The most crucial step to protect your WordPress site from this vulnerability is to update your Quiz and Survey Master plugin immediately. While specific patch details are not always public at the time of initial disclosure, developers typically release a patched version soon after a vulnerability is identified. Always keep your plugins, themes, and WordPress core updated to their latest versions to ensure you have the most recent security fixes.
If an immediate update is not available, or if you need more time to test the update, consider temporarily disabling the Quiz and Survey Master plugin until you can safely apply the patch. Additionally, regularly back up your WordPress site, especially before making any major updates, to ensure you can restore data if needed. Review user roles and permissions on your site, granting only the necessary capabilities to minimize potential damage from any authenticated vulnerability.
References
https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.2.6/php/admin/options-page-questions-tab.php#L1116
https://www.wordfence.com/threat-intel/vulnerabilities/id/55895508-d0ef-4855-8d15-b8a45ba0dcb2?source=cve


