Impact
The Quick quotes WordPress plugin up to version 1.0.0 lacks authentication and nonce checks on an AJAX action that writes options. An attacker can specify any option name and value, allowing arbitrary site settings to be altered without logging in. This flaw undermines the integrity of the site’s configuration and can render the site unavailable or disrupt its normal operation. The weakness stems from improper access control, as the plugin does not verify user privileges before processing the request.
Affected Systems
Any WordPress site that has the Quick quotes plugin installed at version 1.0.0 or earlier is vulnerable; the vendor is listed simply as Unknown:Quick quotes, indicating no publicly known maintainer. No newer versions are mentioned in the data, so the issue likely persists until the plugin is updated or removed.
Risk and Exploitability
The vulnerability carries a high potential impact because it permits unauthenticated modification of critical options. The lack of an EPSS score makes precise exploitation probability unknown, but the clear remote web‑based attack vector and absence of authentication requirements suggest a serious risk. The plugin is not listed in CISA’s KEV catalog, yet the possibility of disabling the site makes it a priority for remediation.
OpenCVE Enrichment