CVE-2014-5185: Quartz Plugin Project Quartz Plugin

Medium severity, CVSS 6.0. EPSS: 1.9% chance of exploitation in the next 30 days.

SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edit action in the quartz/quote_form.php page to wp-admin/edit.php.

Affected products

Published 2014-08-06. Last modified 2026-06-17.