Description
The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.
Published: 2026-10-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated configuration modification leading to site downtime
Action: Immediate Patch
AI Analysis

Impact

The Quick quotes WordPress plugin up to version 1.0.0 lacks authentication and nonce checks on an AJAX action that writes options. An attacker can specify any option name and value, allowing arbitrary site settings to be altered without logging in. This flaw undermines the integrity of the site’s configuration and can render the site unavailable or disrupt its normal operation. The weakness stems from improper access control, as the plugin does not verify user privileges before processing the request.

Affected Systems

Any WordPress site that has the Quick quotes plugin installed at version 1.0.0 or earlier is vulnerable; the vendor is listed simply as Unknown:Quick quotes, indicating no publicly known maintainer. No newer versions are mentioned in the data, so the issue likely persists until the plugin is updated or removed.

Risk and Exploitability

The vulnerability carries a high potential impact because it permits unauthenticated modification of critical options. The lack of an EPSS score makes precise exploitation probability unknown, but the clear remote web‑based attack vector and absence of authentication requirements suggest a serious risk. The plugin is not listed in CISA’s KEV catalog, yet the possibility of disabling the site makes it a priority for remediation.

Generated by OpenCVE AI on October 11, 2026 at 08:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Quick quotes plugin to the latest version that addresses the missing authentication check.
  • If an update is not available, remove or disable the Quick quotes plugin entirely to eliminate the vulnerable endpoint.
  • Deploy a server‑side filter or firewall rule to block access to the plugin’s AJAX URL for unauthenticated users, serving as a temporary workaround until the plugin can be updated.

Generated by OpenCVE AI on October 11, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.
Title Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.996Z

Reserved: 2026-09-08T10:52:51.980Z

Link: CVE-2026-86706

cve-icon Vulnrichment

Updated: 2026-10-11T11:22:48.127Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.220

Modified: 2026-10-11T12:17:24.510

Link: CVE-2026-86706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:15:17Z

Weaknesses