Easy Quotes

Easy Quotes has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include SQL Injection.

Every one of the 2 issues recorded for Easy Quotes has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Easy Quotes is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
7.0/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Easy Quotes vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2025-26943

Easy Quotes <= 1.2.2 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

2 records
Easy Quotes banner
Latestv1.3.7
4.7(6)
94/100
Last Updated
2026-08-16 (28d ago)
Active Installs
700+
Downloads
15,566
Requires WP
6.8+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2021-10-05 (5y ago)

Easy Quotes let you collect and display your favorite Quotes / Reviews / Testimonials or any other short snippet of Text you want to present on your site. Main Features: Custom Post Type “Quotes” with Quick Edit and Bulk Actions Add Custom Meta: Author, Date and Rating with Stars Gutenberg Block “Easy Quotes” to present your Collection all over your Site. (Block-Widget/Pages/Posts etc.) Show Random or Daily “Quotes” by Category or choose a Specific Quote. Option to rotate Quotes by Category Option to show Quotes as a List by Category Use Google Fonts and other typographic features to style your Quote. Built to blend into any style, but customizable with CSS to fit your needs. Try my new Plugin Easy Architect

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C