Quotes llama

Quotes llama has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 6 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 4 of the records (67%). Other recurring categories include SQL Injection.

Every one of the 6 issues recorded for Quotes llama has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, most of them (2) reported by Peter Thaleikis. Quotes llama is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

6

Get automatic notifications for all Quotes llama vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2026-56062

Quotes llama <= 3.1.5 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

6 records
Quotes llama banner
Latestv3.1.7

Quotes llama

oooorgle

Author

oooorgle

4.6(30)
92/100
Last Updated
2026-06-26 (3mo ago)
Active Installs
1,000+
Downloads
40,960
Requires WP
6.2.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2016-01-20 (11y ago)

Create a collection of quotes. Share the thoughts that mean the most… display your quotes in block, widget, page, template, gallery or post. Searchable Categories Author and Source Icons Backup (export) and Restore (import) in “.csv or .json” formats. … among other options.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C