
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2468 is a SQL Injection vulnerability in the Quentn WP plugin for WordPress, affecting all versions up to and including 1.2.12. The flaw allows unauthenticated remote attackers to extract sensitive information from the WordPress database by manipulating the qntn_wp_access cookie. It was published on March 21, 2026, with a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability exists in the get_user_access() method within class-quentn-wp-restrict-access.php, where the value of the qntn_wp_access cookie is insufficiently escaped and passed directly into an existing SQL query without proper preparation or parameterization. An unauthenticated attacker can craft a malicious cookie value to append additional SQL statements, enabling blind or union-based data extraction from the database (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to read sensitive data from the WordPress database, including user credentials (hashed passwords), email addresses, session tokens, and any other data stored in the database. The CVSS score reflects a high confidentiality impact with no integrity or availability impact, meaning the attack is limited to data exfiltration rather than modification or disruption. Extracted credentials could facilitate account takeover and further lateral movement within the WordPress environment (Wordfence).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.068%, indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no authentication and no user interaction, making it straightforward to exploit if a target site runs a vulnerable version of the plugin (Wordfence, Red Hat CVE).
readme.txt files at /wp-content/plugins/quentn-wp/readme.txt.get_user_access() method in the Quentn WP plugin, typically pages protected by Quentn access restrictions.qntn_wp_access HTTP cookie to a SQL injection payload, such as a time-based blind injection (e.g., ' OR SLEEP(5)-- -) or a UNION-based payload to extract data.qntn_wp_access cookie value.sqlmap with --cookie="qntn_wp_access=*") to enumerate databases, tables, and extract sensitive records such as wp_users credentials.qntn_wp_access cookie containing SQL metacharacters (e.g., single quotes, UNION, SELECT, SLEEP, --).qntn_wp_access cookie values; anomalous response time variations indicative of time-based blind SQL injection.qntn_wp_access parameter; queries containing UNION SELECT or SLEEP() patterns in database query logs (if enabled).Users should update the Quentn WP plugin to a version beyond 1.2.12 that addresses this vulnerability. Until a patched version is available or applied, administrators should consider disabling the plugin or restricting access to pages that invoke the get_user_access() method via a web application firewall (WAF) rule blocking SQL injection patterns in cookie values. Wordfence users with the firewall enabled may receive automatic protection against exploitation attempts (Wordfence).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the week of March 16–22, 2026, and assigned it a High severity rating (Wordfence Blog). RedPacket Security also published a CVE alert and shared it on social media, contributing to broader community awareness (RedPacket Security). No significant vendor statements from the Quentn plugin developers or major media coverage have been identified beyond standard vulnerability aggregator reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."