Executive brief
Quentn WP is a WordPress plugin that manages page access restrictions. The plugin before version 1.2.15 contains a SQL injection vulnerability in parameters used for sorting page access records. Administrators can exploit this to extract sensitive data from the database, including user password hashes.
Technical details
The plugin fails to properly sanitize and escape the 'orderby' and 'order' parameters before using them in SQL queries. An authenticated administrator (manage_options capability) can inject arbitrary SQL via the orderby or order parameters on the quentn-page-access-overview admin page when viewing pages with access restrictions. Exploitation requires an active administrator session and a page with at least one access record. The vulnerability allows blind time-based SQL injection and blind data extraction; an attacker can byte-by-byte extract data from the wp_users table or other database tables. The issue is fixed in version 1.2.15.
Affected products
- Quentn Quentn WP before 1.2.15
Timeline
- 2026-09-07: disclosed
- 2026-09-15: patched: Fixed in version 1.2.15