CVE-2026-86706
Received Received - Intake

Unauthenticated Settings Modification in Quick Quotes WordPress Plugin

Vulnerability report for CVE-2026-86706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Quick quotes 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin Quick quotes version 1.0.0 or below. It allows unauthenticated users to update arbitrary site settings through an insecure AJAX action that lacks proper capability or nonce checks. This can lead to the site becoming unavailable or compromised.

Detection Guidance

Check if the Quick quotes WordPress plugin version 1.0.0 or below is installed. Look for unauthorized changes to site settings or unusual AJAX requests in server logs.

Impact Analysis

An attacker could exploit this to change site settings, making the website unavailable or taking control of it. Since no authentication is required, anyone could potentially cause significant disruption or security issues.

Compliance Impact

This vulnerability could lead to unauthorized changes to site settings, potentially exposing sensitive data or violating compliance requirements like GDPR or HIPAA if user data is compromised or settings are altered maliciously.

Mitigation Strategies

Immediately disable or uninstall the Quick quotes plugin until a patch is released. Monitor site activity for unauthorized changes and restrict access to admin panels.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart