Sceawere
Vulnerability Detail
CVE-2026-86706UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Settings Change Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Quick quotes
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-11T07:17:26.220Z",
"pubdate": "2026-10-11T07:17:26.220Z",
"executiveSummary": "The Quick quotes WordPress plugin, version 1.0.0 and earlier, contains a critical security vulnerability involving improper authorization and lack of nonces in its AJAX request handling. This vulnerability allows an unauthenticated remote attacker to modify arbitrary site options within the WordPress database.\nThe primary impact of this flaw is the potential for full site compromise or total service unavailability. By leveraging the insecure AJAX endpoint, an attacker can overwrite critical WordPress configuration settings, such as the 'siteurl', 'home', or user registration settings. This can facilitate account takeover, redirect traffic to malicious domains, or render the administration dashboard inaccessible.\nThe vulnerability stems from the plugin's failure to enforce capability checks (e.g., 'manage_options') and the absence of cryptographic nonce validation on an administrative AJAX action. Because the action permits the caller to specify which option is written, an attacker can arbitrarily inject data into the wp_options table without requiring any authentication or administrative privileges. This represents a significant security risk for any site utilizing the affected version of the plugin.",
"technicalDetails": "The vulnerability is rooted in the insecure implementation of an AJAX handler within the Quick quotes plugin. WordPress plugins frequently use the 'wp_ajax_' and 'wp_ajax_nopriv_' hooks to handle asynchronous requests. In this instance, the plugin exposes an AJAX action that accepts user-supplied input to perform write operations on the database without validating the caller's identity or authorization level.\nSpecifically, the vulnerable code fails to call 'check_ajax_referer()' to verify the request's origin via a nonce. Furthermore, it neglects to verify if the current user possesses sufficient permissions—typically checked via 'current_user_can('manage_options')'—before executing the database update operation. This lack of access control creates an insecure direct object reference or an unrestricted administrative function pattern.\nThe attack flow begins with an unauthenticated attacker identifying the AJAX endpoint exposed by the plugin. The attacker then crafts an HTTP POST request targeting 'wp-admin/admin-ajax.php'. The payload of this request includes the vulnerable action name and parameters that dictate which option key is targeted and what value should be written to it. Because the underlying code directly processes these inputs to update the 'wp_options' table, the attacker can systematically alter the configuration of the WordPress site.\nPost-exploitation scenarios include, but are not limited to, updating the 'active_plugins' option to disable security plugins, modifying the 'users_can_register' and 'default_role' settings to permit the creation of administrative accounts, or altering 'siteurl' and 'home' to redirect all legitimate traffic to a malicious site controlled by the attacker. By changing the 'admin_email' or other site configuration parameters, an attacker can also establish persistence or intercept sensitive administrative communications.\nThe flaw affects Quick quotes versions through 1.0.0. The lack of network exposure restrictions implies that any public-facing installation of this plugin is inherently vulnerable to remote exploitation, provided the attacker can reach the 'admin-ajax.php' file. The vulnerability is characterized by a complete bypass of the WordPress administrative authentication layer, allowing the attacker to interact with the database as if they were a high-privileged administrator."
}