Junglewise Threat Intelligence

CVE-2026-18143: Request a Quote for WooCommerce arbitrary file upload

CVE-2026-18143 · Severity: critical · CVSS 9.8 · Published 2026-09-26

Executive brief

The Request a Quote for WooCommerce plugin allows customers to submit quotation requests with file uploads. An unauthenticated attacker can bypass file upload restrictions and upload executable PHP files to the web server, enabling remote code execution and complete compromise of the WordPress site. This affects all versions up to 2.9.2.

Technical details

The vulnerability exists in the afrfq_submit_quote_via_popup() function, which lacks proper validation of file extensions and MIME types in the popup upload handler. The raw attacker-supplied filename is passed directly to move_uploaded_file(), allowing PHP files to be uploaded to the web-accessible temporary RFQ upload directory. Exploitation requires only that a public quote rule with multi-page popup flow is enabled, and no authentication is required.

Affected products

  • Addify Request a Quote for WooCommerce up to and including 2.9.2

Timeline

  • 2026-09-26: disclosed

References