CVE-2026-86706 PUBLISHED

Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update

Assigner: WPScan
Reserved: 08.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.

Product Status

Vendor Unknown
Product Quick quotes
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE