CRITICAL 9.1 CVE-2026-86706 Published 11 Oct 2026

Quick Quotes WordPress Plugin Missing Auth Lets Unauthenticated Users Change Settings

Worried this affects your website?

The Quick quotes WordPress plugin through 1.0.0 has a missing authorization vulnerability in one of its AJAX actions. The action does not perform any capability or nonce check, and lets the caller choose which option is written.

  • No capability or nonce check is performed on the AJAX action.
  • The caller can choose which option is written.
  • Unauthenticated users can alter arbitrary site settings.
  • The site can be made unavailable.

Reference: CVE-2026-86706 on NVD

← Back to Security News