CRITICAL
9.1 CVE-2026-86706 Published 11 Oct 2026
Quick Quotes WordPress Plugin Missing Auth Lets Unauthenticated Users Change Settings
Worried this affects your website?
The Quick quotes WordPress plugin through 1.0.0 has a missing authorization vulnerability in one of its AJAX actions. The action does not perform any capability or nonce check, and lets the caller choose which option is written.
- No capability or nonce check is performed on the AJAX action.
- The caller can choose which option is written.
- Unauthenticated users can alter arbitrary site settings.
- The site can be made unavailable.
Reference: CVE-2026-86706 on NVD
← Back to Security News