Sensitive Data Exposure in QuarkA QA Analytics Plugin
CVE-2026-105877

6.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-105877?

The QuarkA QA Analytics plugin is susceptible to a vulnerability that allows the retrieval of embedded sensitive information. This flaw enables unauthorized access to sensitive data that could be manipulated or exploited. Users of versions up to 5.3.0.0 are strongly advised to update their plugin to safeguard against potential data breaches and risks to their systems. Enhanced security measures should be implemented to protect sensitive information from exposure.

Affected Version(s)

QA Analytics 0 <= 5.3.0.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.