WordPress Plugin Vulnerabilities

Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR

Description

The plugin does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.

Proof of Concept

Affects Plugins

Fixed in 11.2.4

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-17 (about 2 days ago)

Other