Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Blind SQL Injection.This issue affects Easy Quotes: from n/a through <= 1.2.2.
Published: 2025-02-25
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Quotes plugin for WordPress has a blind SQL injection flaw due to improper neutralization of special elements in SQL commands. Attackers can craft input that is passed directly to the database, allowing them to extract or alter sensitive data stored by WordPress. This vulnerability can expose user credentials, site configuration, and other confidential information, potentially compromising the integrity of the entire site.

Affected Systems

All installations of the Easy Quotes plugin for WordPress up to and including version 1.2.2 are affected. The vulnerable versions include any release from the first to the 1.2.2 release. Users running these versions on WordPress sites should treat the plugin as vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, indicating high severity. The EPSS score of less than 1% suggests a low current probability of widespread exploitation, and it is not listed in the CISA KEV catalog. However, the attack vector is likely through the web interface of the plugin, requiring only HTTP access to the site. An attacker can send specially crafted requests to the plugin’s input points and use the blind SQL injection to read or modify data by observing side effects, such as response timing or error messages. No authentication is required, making the flaw accessible to anyone who can reach the site’s front-end.

Generated by OpenCVE AI on May 1, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Quotes to the latest patched version (or uninstall if no upgrade is available).
  • If an update is not feasible, disable or remove the plugin entirely until a fix is released.
  • Restrict the WordPress database user to the least privileges needed (e.g., no DROP or EXECUTE rights) so that even if an injection succeeds the damage is limited.

Generated by OpenCVE AI on May 1, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5439 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes allows Blind SQL Injection. This issue affects Easy Quotes: from n/a through 1.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes allows Blind SQL Injection. This issue affects Easy Quotes: from n/a through 1.2.2. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Blind SQL Injection.This issue affects Easy Quotes: from n/a through <= 1.2.2.
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes allows Blind SQL Injection. This issue affects Easy Quotes: from n/a through 1.2.2.
Title WordPress Easy Quotes plugin <= 1.2.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:44.353Z

Reserved: 2025-02-17T11:51:18.743Z

Link: CVE-2025-26943

cve-icon Vulnrichment

Updated: 2025-02-25T14:56:36.996Z

cve-icon NVD

Status : Deferred

Published: 2025-02-25T15:15:28.030

Modified: 2026-06-17T09:02:38.623

Link: CVE-2025-26943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:30:20Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')