Executive brief
Quotes llama, a WordPress plugin used to manage and display quotes on websites, contains a security flaw that allows unauthorized individuals to access the site's database. By exploiting this vulnerability, an attacker can steal sensitive information, including user account names and encrypted password hashes. This could lead to full site takeover if the stolen credentials are cracked or reused.
Technical details
The Quotes llama plugin for WordPress fails to properly sanitize and escape the 'sc' parameter before incorporating it into SQL queries within the 'select_search' and 'select_search_page' AJAX actions. An unauthenticated attacker can exploit this by obtaining a public nonce from a page using the plugin's shortcode and then sending a crafted POST request to wp-admin/admin-ajax.php. This allows for UNION-based SQL injection, enabling the extraction of arbitrary data from the WordPress database, such as user logins and password hashes from the wp_users table. The issue is resolved in version 3.1.6.
Affected products
- Unknown Quotes llama before 3.1.6
Timeline
- 2026-06-24: disclosed: Publicly published by researchers
- 2026-07-15: advisory: CVE published to NVD dataset
- 2026-07-15: patched: Fixed in version 3.1.6