CVE-2026-86706: Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update
Published Oct 11, 2026
·Updated
The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.
Affected Software
1 affected component
Quick quotes<=1.0.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness