Quote Comments [quote-comments] <= 3.0.0 (unfixed)
unknown
[en] The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.0. This is due to missing authorization checks in the quotecomments_add_admin function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbi...
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 7, 2026
CVE-2025-14370 on NVD →
Quote Comments <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update
medium
The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.0. This is due to missing authorization checks in the quotecomments_add_admin function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary...
- CVSS:
- 4.3
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-14370 on NVD →
Quote Comments [quote-comments] <= 3.0.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments allows Stored XSS. This issue affects Quote Comments: from n/a through 2.2.1.
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 7, 2025
CVE-2025-25156 on NVD →
Quote Comments <= 3.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Quote Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged reque...
- CVSS:
- 6.1
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2025
CVE-2025-25156 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database