Description
Missing Authorization vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Quotes: from n/a through <= 1.2.4.
Published: 2025-09-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control security levels in the WordPress Easy Quotes plugin. The flaw lets a user perform actions normally reserved for privileged roles, such as creating, editing, or deleting quotes, and potentially altering plugin settings. Consequently, an attacker can gain unauthorized control over content displayed by the site and may undermine the integrity of posted quotes.

Affected Systems

The Easy Quotes plugin for WordPress, developed by Jürgen Müller, is affected on all released versions up to and including 1.2.4. Any WordPress installation that has a version of Easy Quotes 1.2.4 or earlier is vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% means the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Although the attack vector is not explicitly stated in the description, it is reasonable to infer that the flaw could be abused by any user who can reach the plugin’s management interface, either authenticated or possibly unauthenticated if the site’s settings expose the plugin’s configuration. Because the issue arises from misconfigured access controls, it can be leveraged to execute privileged actions once the attacker can reach the plugin.

Generated by OpenCVE AI on April 30, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Quotes to a version newer than 1.2.4.
  • Confirm that the plugin’s configuration enforces proper role-based access controls and that only authorized administrators can manage quotes.
  • Review other WordPress plugins for similar broken access control issues and apply updates or patches when available.

Generated by OpenCVE AI on April 30, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30522 Missing Authorization vulnerability in Jürgen Müller Easy Quotes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy Quotes: from n/a through 1.2.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Jürgen Müller Easy Quotes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy Quotes: from n/a through 1.2.4. Missing Authorization vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Quotes: from n/a through <= 1.2.4.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Jürgen Müller Easy Quotes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy Quotes: from n/a through 1.2.4.
Title WordPress Easy Quotes Plugin <= 1.2.4 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:55:59.511Z

Reserved: 2025-09-03T09:03:46.832Z

Link: CVE-2025-58681

cve-icon Vulnrichment

Updated: 2025-09-23T13:57:50.366Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:19.590

Modified: 2026-04-23T15:33:35.173

Link: CVE-2025-58681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:00:13Z

Weaknesses