
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Security & Risk Analysis
wordpress.org/plugins/quiz-master-nextCreate quizzes, surveys, and tests easily on WordPress with this versatile plugin. Perfect for engaging any audience and gathering valuable insights!
Is Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Safe to Use in 2026?
Mostly Safe
Score 76/100Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is generally safe to use. 57 past CVEs were resolved. Keep it updated.
The security posture of Quiz Master Next v10.3.5 presents a mixed bag, with some strong security practices offset by significant areas of concern. The plugin demonstrates good practices in its use of prepared statements for SQL queries and a high percentage of properly escaped outputs, indicating an effort to mitigate common web vulnerabilities. However, the presence of a dangerous `unserialize` function, coupled with a substantial number of unsanitized taint flows, particularly those of high severity, raises serious red flags regarding potential deserialization and code execution vulnerabilities. The large number of unprotected AJAX handlers and REST API routes further expands the attack surface, making these entry points prime targets for exploitation if authorization checks are insufficient.
The plugin's vulnerability history is a major concern, with a staggering 57 known CVEs. While there are currently no unpatched vulnerabilities, the sheer volume and the prevalence of critical and high-severity past issues, including deserialization, XSS, CSRF, and SQL injection, strongly suggest recurring security weaknesses in the development lifecycle. This pattern indicates a persistent struggle with robust input validation and secure coding practices across various vulnerability types. The last reported vulnerability in 2026 also suggests a potential for newly discovered issues or a lag in security patching if the codebase remains stagnant.
In conclusion, while Quiz Master Next v10.3.5 shows some strengths in output sanitization and SQL query handling, the identified risks in its code analysis (unprotected entry points, dangerous functions, high-severity taint flows) and its extensive history of critical and high-severity vulnerabilities paint a picture of a plugin that requires significant attention to security. The potential for deserialization attacks and exploitation of its broad unprotected attack surface are the most pressing threats, compounded by the historical tendency for severe security flaws.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function: unserialize
- High severity unsanitized taint flows
- High number of critical/high past CVEs
- Large attack surface
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Security Vulnerabilities
CVEs by Year
Severity Breakdown
57 total CVEs
Quiz And Survey Master <= 10.3.1 - Authenticated (Subscriber+) SQL Injection
Quiz And Survey Master <= 10.3.3 - Missing Authorization
Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads
Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter
Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion
Quiz And Survey Master <= 10.3.2 - Missing Authorization
Quiz And Survey Master <= 10.2.5 - Unauthenticated PHP Object Injection
Quiz And Survey Master <= 10.2.4 - Authenticated (Contributor+) SQL Injection
Quiz and Survey Master (QSM) <= 10.2.2 - Cross-Site Request Forgery to Template Creation
Quiz and Survey Master (QSM) <= 9.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Quiz and Survey Master (QSM) <= 9.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Quiz and Survey Master (QSM) <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz and Survey Master <= 9.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz and Survey Master <= 9.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 9.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection
Quiz And Survey Master <= 8.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Quiz And Survey Master <= 8.1.18 - Cross-Site Request Forgery
Quiz And Survey Master <= 8.1.16 - Missing Authorization
Quiz And Survey Master <= 8.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master <= 8.1.15 - Cross-Site Request Forgery via 'display_results'
Quiz And Survey Master <= 8.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Question Title
Quiz And Survey Master <= 8.1.10 - Excessive Quiz Attempts
Quiz and Survey Master <= 8.1.4 - Unauthenticated SQL Injection
Quiz And Survey Master <= 8.0.10 - Cross-Site Request Forgery to Quiz Restoration
Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion
Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion
Quiz And Survey Master <= 8.0.7 - Cross-Site Request Forgery
Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer
Quiz and Survey Master <= 8.0.4 - Improper Input Validation
Quiz And Survey Master <= 7.3.10 - Cross-Site Request Forgery
Quiz And Survey Master <= 7.3.4 - Authenticated (Administrator+) SQL Injection
Quiz And Survey Master <= 7.3.6 - Insecure Direct Object Reference
Quiz And Survey Master <= 7.3.10 - Unauthenticated Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.4 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 7.3.10 - Missing Authorization
Quiz And Survey Master <= 7.3.4 - Multiple Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.10 - Sensitive Information Disclosure
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 7.3.4 - Insecure Direct Object Reference
Quiz And Survey Master <= 7.3.6 - Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.6 - Cross-Site Request Forgery
Quiz And Survey Master <= 7.3.6 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 7.3.1 - Admin+ Stored Cross-Site Scripting
Quiz and Survey Master <= 7.1.13 - Cross-Site Scripting
Quiz and Survey Master <= 7.1.13 - SQL Injection
Quiz And Survey Master <= 7.1.18 - Cross-Site Scripting
Quiz And Survey Master <= 7.1.17 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 7.1.11 - Authenticated SQL injection via shortcode
Quiz and Survey Master <= 7.0.1 - Arbitrary File Upload
Quiz and Survey Master <= 7.0.0 - Unauthenticated Arbitrary File Deletion
Quiz and Survey Master <= 7.0.0 - Arbitrary File Upload
Quiz and Survey Master <= 6.4.12 - Stored Cross-Site Scripting
Quiz And Survey Master <= 6.3.4 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 6.2.1 - Cross-Site Scripting
Quiz And Survey Master <= 4.7.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Quiz And Survey Master < 4.4.4 - Multiple SQL Injections
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Attack Surface
AJAX Handlers 32
REST API Routes 22
Shortcodes 5
WordPress Hooks 162
Maintenance & Trust
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Maintenance & Trust
Maintenance Signals
Community Trust
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Alternatives
Watu Quiz
watu
Creates exams, surveys, and quizzes with unlimited number of questions and answers. Mobile/touch - friendly.
Chained Quiz
chained-quiz
Create a quiz where the next question depends on the answer to the previous question. Final quiz results depend on the amount of collected points.
Quiz Creator – Easy Quiz, Survey & Test Maker
quiz-creator
Create and manage interactive quizzes with multiple question types, automatic scoring, timed quizzes, and email notifications.
Watu to MailChimp
watu-bridge-to-mailchimp
A bridge between the Watu Quiz plugin and MailChimp /*** This program is free software: you can redistribute it and/or modify it under the terms of …
WpCues Basic Quiz
wpcues-basic-quiz
Create math / html / multimedia rich quiz. Award Mozilla Open Badges, Create colorful charts / leader boards and sell your quizzes using stripe.
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Developer Profile
21 plugins · 122K total installs
How We Detect Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quiz-master-next/css/style.css/wp-content/plugins/quiz-master-next/js/quiz_master_next.js/wp-content/plugins/quiz-master-next/js/public/quiz-master-next-frontend.js/wp-content/plugins/quiz-master-next/js/admin/quiz-master-next-admin.js/wp-content/plugins/quiz-master-next/css/admin/quiz-master-next-admin.css/wp-content/plugins/quiz-master-next/js/quiz_master_next.js/wp-content/plugins/quiz-master-next/js/public/quiz-master-next-frontend.js/wp-content/plugins/quiz-master-next/js/admin/quiz-master-next-admin.jsquiz-master-next/style.css?ver=quiz-master-next/js/quiz_master_next.js?ver=quiz-master-next/js/public/quiz-master-next-frontend.js?ver=quiz-master-next/js/admin/quiz-master-next-admin.js?ver=quiz-master-next/css/admin/quiz-master-next-admin.css?ver=HTML / DOM Fingerprints
qsm_custom_cssQSM Debug InfoSTART QSM Debug InfoEND QSM Debug Infodata-quiz_iddata-quiz_namedata-quiz_result_typeqsm_ajax_objectquiz_master_next_global/wp-json/quizmaster_next/v1/quiz_data/wp-json/quizmaster_next/v1/quiz_submit[quiz_master_next]