Request a Quote for WooCommerce Plugin Arbitrary File Upload
The Request a Quote for WooCommerce plugin through version 2.9.2 allows unauthenticated attackers to upload arbitrary files via the quote submission endpoint. CVSS 9.8 critical, patched in version 2.9.3.
- Vendor
- Addify
- Product
- Request a Quote for WooCommerce
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
CVE-2026-18143 is an arbitrary file upload vulnerability in the Request a Quote for WooCommerce plugin (by Addify) affecting all versions through 2.9.2. The flaw exists in the afrfq_submit_quote_via_popup() function, which handles file attachments in quote submission requests without enforcing authentication. An unauthenticated attacker can reach the endpoint directly and upload files of arbitrary type.
The vendor released version 2.9.3 to address the flaw. Site operators should update through the WordPress plugin dashboard or by downloading directly from the WooCommerce marketplace. Full technical details are in the NVD record.
