PT-2026-26838 · WordPress · Quentn Wp

Nabil Irawan

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-2468

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quentn WP plugin for WordPress versions through 1.2.12
Description The Quentn WP plugin for WordPress is susceptible to SQL Injection due to inadequate input sanitization and insufficient SQL query preparation. Specifically, the vulnerability resides in the get user access() method and affects the qntn wp access cookie. This allows unauthenticated attackers to inject additional SQL queries, potentially leading to the extraction of sensitive information from the database.
Recommendations Update the Quentn WP plugin to a version later than 1.2.12.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2468

Affected Products

Quentn Wp