OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-18143

CRITICAL · CVSS 9.8 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to inadequate validation of file extensions and MIME types in the upload handler. This flaw allows unauthenticated attackers to upload malicious executable files, such as PHP scripts, to a publicly accessible directory, potentially leading to remote code execution. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-18143
Severity
CRITICAL
CVSS
9.8
EPSS
0.41%
WordPress

Original NVD Description

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled.