Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-18143

Request a Quote for WooCommerce Plugin Arbitrary File Upload

The Request a Quote for WooCommerce plugin through version 2.9.2 allows unauthenticated attackers to upload arbitrary files via the quote submission endpoint. CVSS 9.8 critical, patched in version 2.9.3.

cat cve-2026-18143.json
Vendor
Addify
Product
Request a Quote for WooCommerce
CVSS
9.8
EPSS (exploit probability)
0.4%
Status
patched
Published

CVE-2026-18143 is an arbitrary file upload vulnerability in the Request a Quote for WooCommerce plugin (by Addify) affecting all versions through 2.9.2. The flaw exists in the afrfq_submit_quote_via_popup() function, which handles file attachments in quote submission requests without enforcing authentication. An unauthenticated attacker can reach the endpoint directly and upload files of arbitrary type.

The vendor released version 2.9.3 to address the flaw. Site operators should update through the WordPress plugin dashboard or by downloading directly from the WooCommerce marketplace. Full technical details are in the NVD record.