Description
The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.
Published: 2026-09-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Patch
AI Analysis

Impact

The Quentn WP WordPress plugin prior to version 1.2.15 contains a vulnerability where a request parameter named 'qntn_wp' is not properly escaped before being used in an unprepared SQL query. This omission permits SQL injection, allowing an unauthenticated attacker to craft malicious input that can extract or manipulate arbitrary data stored in the database. The affected systems could therefore expose sensitive information such as user credentials, content, or configuration details without any authentication or authorization barriers.

Affected Systems

The vulnerability affects the Quentn WP plugin for WordPress, specifically versions 1.2.13 and 1.2.14. Based on the description, it is inferred that earlier releases that include the same code path may also be affected.

Risk and Exploitability

Attackers can execute arbitrary SQL through the unescaped 'qntn_wp' parameter with no authentication and a simple HTTP request. The CVSS score of 8.6 highlights a high severity risk. The EPSS score of less than 1% suggests a low probability of exploitation, while the vulnerability remains absent from CISA's KEV catalog. Nonetheless, the potential for data extraction persists on impacted WordPress installations.

Generated by OpenCVE AI on September 9, 2026 at 18:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Quentn WP to version 1.2.15 or newer to ensure proper input sanitization.
  • If an upgrade is not immediately possible, prevent unauthenticated access to the vulnerable 'qntn_wp' endpoint by disabling or removing it and restricting any remaining functionality to authenticated users only.
  • Deploy a Web Application Firewall rule that blocks SQL injection attempts targeting the 'qntn_wp' parameter to provide temporary protection.

Generated by OpenCVE AI on September 9, 2026 at 18:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.
Title Quentn WP 1.2.13 - 1.2.14 - Unauthenticated SQLi via 'qntn_wp' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:37:25.744Z

Reserved: 2026-09-01T06:07:37.984Z

Link: CVE-2026-84068

cve-icon Vulnrichment

Updated: 2026-09-09T15:36:29.366Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:17.830

Modified: 2026-09-09T16:17:12.477

Link: CVE-2026-84068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T19:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')