Description
The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.
Published: 2026-09-09
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The Quentn WP WordPress plugin before version 1.2.15 contains an unsanitised 'orderby'/'order' parameter that is inserted directly into an SQL query. Administrators can exploit this to inject arbitrary SQL commands, enabling data exfiltration, modification, or deletion. The vulnerability allows attackers with high privileges to compromise database confidentiality, integrity, and availability, potentially leading to full site compromise.

Affected Systems

Any WordPress installation that uses the Quentn WP plugin at a version lower than 1.2.15 is affected. The plugin, provided by an unknown vendor, is typically found in WordPress sites as a plugin named Quentn WP.

Risk and Exploitability

Because the flaw requires an account with administrator rights to manipulate the vulnerable parameters, the attack vector is primarily local within the application, but once exploited an attacker can execute arbitrary SQL directly against the database. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV. The CVSS score of 4.1 indicates a low severity, suggesting that the risk level is moderate rather than critical in this privileged context.

Generated by OpenCVE AI on September 9, 2026 at 18:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Quentn WP plugin to version 1.2.15 or later to apply the SQL injection fix.
  • If an upgrade is delayed, block the vulnerable 'orderby'/'order' query parameters with a web application firewall or modify the plugin code to sanitize input.
  • Perform a full database backup before applying the update and monitor database logs for anomalous queries after the change.

Generated by OpenCVE AI on September 9, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.
Title Quentn WP < 1.2.15 - Admin+ SQLi via 'orderby'/'order' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:29:23.368Z

Reserved: 2026-09-01T07:14:54.114Z

Link: CVE-2026-84113

cve-icon Vulnrichment

Updated: 2026-09-09T15:28:58.882Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:17.937

Modified: 2026-09-09T16:17:12.660

Link: CVE-2026-84113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T19:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')