{"id":"CVE-2026-84113","title":"The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.","summary":"The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.","severity":"medium","cvss":4.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N","cwe":["CWE-89"],"product":"Quentn WP","affected":["quentn_wp < 1.2.15"],"published":"2026-09-09","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:17:12.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84113","references":[{"url":"https://wpscan.com/vulnerability/359127b1-94a5-4007-94ac-a1d813b04ce0/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-09T15:29:18.199327Z"},"epss":0.00186,"epssPercentile":0.0843,"ingestedAt":"2026-09-09T07:03:03.594Z","slug":"CVE-2026-84113","body":"## Overview\n\nThe Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":22.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":19678,"id":"CVE-2026-84113","ts":1788970490409,"field":"cvss","old":null,"new":"4.1"},{"seq":19677,"id":"CVE-2026-84113","ts":1788970490409,"field":"severity","old":"none","new":"medium"}]}