Junglewise Threat Intelligence

CVE-2026-8884: Instant-Quote.co Quotation Page stored XSS via shortcode attributes

CVE-2026-8884 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Executive brief

The Instant-Quote.co Quotation Page plugin for WordPress, which allows businesses to provide automated quotes to customers, contains a security flaw. This vulnerability allows users with basic contributor access to inject malicious scripts into website pages. These scripts can then target site administrators, potentially leading to unauthorized actions or account takeover when the administrator views the affected content.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw located in the Instant-Quote.co Quotation Page plugin for WordPress. It stems from insufficient input sanitization and output escaping of shortcode attributes. An authenticated attacker with at least contributor-level permissions can exploit this by embedding malicious scripts within a shortcode. When a higher-privileged user, such as an administrator, previews or views the post containing the malicious shortcode, the script executes in their browser context. This can lead to session hijacking or unauthorized administrative actions. All versions up to and including 1.3.4 are affected.

Affected products

  • Instant-Quote.co Instant-Quote.co Quotation Page up to, and including, 1.3.4

Timeline

  • 2026-05-27: disclosed: Initial publication of the CVE record.
  • 2026-05-27: advisory: Wordfence published the vulnerability details.

References