Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18143— Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler

Quick assessment

Affected
Addify Request a Quote for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 “Request a Quote for WooCommerce” 插件在所有 2.9.2 及以下版本中存在任意文件上传漏洞,该漏洞源于 函数。由于弹出式上传处理程序未对文件扩展名和 MIME 类型进行验证,而是直接将攻击者提供的原始文件名用作 函数的目标路径,因此未认证的攻击者在启用了具有多页面弹出流程的公开报价规则时,能够将可执行文件(如 PHP 文件)上传至网页可访问的临时 RFQ 上传目录。

CVSS 9.8 · Critical EPSS 0.41% · P33
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18143

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler
Source: CVE Program / CVE List V5
Vulnerability Description
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Addify Request a Quote for WooCommerce 0 ~ 2.9.2 -

II. Public POCs for CVE-2026-18143

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18143

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-18143 (1)

Other References for CVE-2026-18143 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18143

No comments yet


Leave a comment