
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Security & Risk Analysis
wordpress.org/plugins/quiz-master-nextQuiz maker & survey maker for WordPress. Build quizzes, surveys, exams & assessments with scoring, results pages & lead capture — free & easy.
Is Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Safe to Use in 2026?
Mostly Safe
Score 76/100Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker is generally safe to use. 66 past CVEs were resolved.
The security posture of Quiz Master Next v10.3.5 presents a mixed bag, with some strong security practices offset by significant areas of concern. The plugin demonstrates good practices in its use of prepared statements for SQL queries and a high percentage of properly escaped outputs, indicating an effort to mitigate common web vulnerabilities. However, the presence of a dangerous `unserialize` function, coupled with a substantial number of unsanitized taint flows, particularly those of high severity, raises serious red flags regarding potential deserialization and code execution vulnerabilities. The large number of unprotected AJAX handlers and REST API routes further expands the attack surface, making these entry points prime targets for exploitation if authorization checks are insufficient.
The plugin's vulnerability history is a major concern, with a staggering 57 known CVEs. While there are currently no unpatched vulnerabilities, the sheer volume and the prevalence of critical and high-severity past issues, including deserialization, XSS, CSRF, and SQL injection, strongly suggest recurring security weaknesses in the development lifecycle. This pattern indicates a persistent struggle with robust input validation and secure coding practices across various vulnerability types. The last reported vulnerability in 2026 also suggests a potential for newly discovered issues or a lag in security patching if the codebase remains stagnant.
In conclusion, while Quiz Master Next v10.3.5 shows some strengths in output sanitization and SQL query handling, the identified risks in its code analysis (unprotected entry points, dangerous functions, high-severity taint flows) and its extensive history of critical and high-severity vulnerabilities paint a picture of a plugin that requires significant attention to security. The potential for deserialization attacks and exploitation of its broad unprotected attack surface are the most pressing threats, compounded by the historical tendency for severe security flaws.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function: unserialize
- High severity unsanitized taint flows
- High number of critical/high past CVEs
- Large attack surface
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Security Vulnerabilities
CVEs by Year
Severity Breakdown
66 total CVEs
Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure
Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action
Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.1.2 - Unauthenticated Stored Cross-Site Scripting
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.0.0 - Unauthenticated Stored Cross-Site Scripting
Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields
Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 10.3.4 - Missing Authorization
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 10.3.4 - Unauthenticated Insecure Direct Object Reference
Quiz And Survey Master <= 10.3.1 - Authenticated (Subscriber+) SQL Injection
Quiz And Survey Master <= 10.3.3 - Missing Authorization
Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads
Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter
Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion
Quiz And Survey Master <= 10.3.2 - Missing Authorization
Quiz And Survey Master <= 10.2.5 - Unauthenticated PHP Object Injection
Quiz And Survey Master <= 10.2.4 - Authenticated (Contributor+) SQL Injection
Quiz and Survey Master (QSM) <= 10.2.2 - Cross-Site Request Forgery to Template Creation
Quiz and Survey Master (QSM) <= 9.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Quiz and Survey Master (QSM) <= 9.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Quiz and Survey Master (QSM) <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz and Survey Master <= 9.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz and Survey Master <= 9.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 9.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection
Quiz And Survey Master <= 8.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Quiz And Survey Master <= 8.1.18 - Cross-Site Request Forgery
Quiz And Survey Master <= 8.1.16 - Missing Authorization
Quiz And Survey Master <= 8.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master <= 8.1.15 - Cross-Site Request Forgery via 'display_results'
Quiz And Survey Master <= 8.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Question Title
Quiz And Survey Master <= 8.1.10 - Excessive Quiz Attempts
Quiz and Survey Master <= 8.1.4 - Unauthenticated SQL Injection
Quiz And Survey Master <= 8.0.10 - Cross-Site Request Forgery to Quiz Restoration
Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion
Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion
Quiz And Survey Master <= 8.0.7 - Cross-Site Request Forgery
Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer
Quiz and Survey Master <= 8.0.4 - Improper Input Validation
Quiz And Survey Master <= 7.3.10 - Cross-Site Request Forgery
Quiz And Survey Master <= 7.3.4 - Authenticated (Administrator+) SQL Injection
Quiz And Survey Master <= 7.3.6 - Insecure Direct Object Reference
Quiz And Survey Master <= 7.3.10 - Unauthenticated Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.4 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 7.3.10 - Missing Authorization
Quiz And Survey Master <= 7.3.4 - Multiple Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.10 - Sensitive Information Disclosure
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 7.3.4 - Insecure Direct Object Reference
Quiz And Survey Master <= 7.3.6 - Stored Cross-Site Scripting
Quiz And Survey Master <= 7.3.6 - Cross-Site Request Forgery
Quiz And Survey Master <= 7.3.6 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 7.3.1 - Admin+ Stored Cross-Site Scripting
Quiz and Survey Master <= 7.1.13 - Cross-Site Scripting
Quiz and Survey Master <= 7.1.13 - SQL Injection
Quiz And Survey Master <= 7.1.18 - Cross-Site Scripting
Quiz And Survey Master <= 7.1.17 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 7.1.11 - Authenticated SQL injection via shortcode
Quiz and Survey Master <= 7.0.1 - Arbitrary File Upload
Quiz and Survey Master <= 7.0.0 - Unauthenticated Arbitrary File Deletion
Quiz and Survey Master <= 7.0.0 - Arbitrary File Upload
Quiz and Survey Master <= 6.4.12 - Stored Cross-Site Scripting
Quiz And Survey Master <= 6.3.4 - Reflected Cross-Site Scripting
Quiz And Survey Master <= 6.2.1 - Cross-Site Scripting
Quiz And Survey Master <= 4.7.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Quiz And Survey Master < 4.4.4 - Multiple SQL Injections
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Release Timeline
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Attack Surface
AJAX Handlers 32
REST API Routes 22
Shortcodes 5
WordPress Hooks 162
Maintenance & Trust
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Maintenance & Trust
Maintenance Signals
Community Trust
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Alternatives
involve.me – Create Surveys, Quizzes, Calculators & Forms as Embedded Widgets or Pop-ups
involve-me
Add forms, quizzes, surveys and interactive calculators to your WordPress site. Easily embed or use as pop-ups. No coding required.
Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site
riddle-playful-content-on-the-go
Riddle’s beautifully intuitive quiz maker lets you create unlimited quizzes, personality tests, and more—no coding, no limits.
Quiz Maker by AYS
quiz-maker
QUIZ MAKER plugin allows you to make an unlimited number of Quizzes, Exams and Tests
HD Quiz
hd-quiz
Create a Quiz. An easy-to-use feature rich plugin to create quizzes with quiz timer, pagination, hints, advanced marking, and leading help and support
Quiz Maker, Poll Maker & Survey Maker by Opinion Stage
social-polls-by-opinionstage
Boost engagement and capture leads with interactive quizzes, polls, and surveys. Built for marketers, publishers, and businesses
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker Developer Profile
22 plugins · 112K total installs
How We Detect Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quiz-master-next/css/style.css/wp-content/plugins/quiz-master-next/js/quiz_master_next.js/wp-content/plugins/quiz-master-next/js/public/quiz-master-next-frontend.js/wp-content/plugins/quiz-master-next/js/admin/quiz-master-next-admin.js/wp-content/plugins/quiz-master-next/css/admin/quiz-master-next-admin.css/wp-content/plugins/quiz-master-next/js/quiz_master_next.js/wp-content/plugins/quiz-master-next/js/public/quiz-master-next-frontend.js/wp-content/plugins/quiz-master-next/js/admin/quiz-master-next-admin.jsquiz-master-next/style.css?ver=quiz-master-next/js/quiz_master_next.js?ver=quiz-master-next/js/public/quiz-master-next-frontend.js?ver=quiz-master-next/js/admin/quiz-master-next-admin.js?ver=quiz-master-next/css/admin/quiz-master-next-admin.css?ver=HTML / DOM Fingerprints
qsm_custom_cssQSM Debug InfoSTART QSM Debug InfoEND QSM Debug Infodata-quiz_iddata-quiz_namedata-quiz_result_typeqsm_ajax_objectquiz_master_next_global/wp-json/quizmaster_next/v1/quiz_data/wp-json/quizmaster_next/v1/quiz_submit[quiz_master_next]