CRITICAL
9.8 CVE-2026-18143 Published 26 Sept 2026
Request a Quote for WooCommerce Plugin Arbitrary File Upload Vulnerability
Worried this affects your website?
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to and including 2.9.2.
The flaw exists in the afrfq_submit_quote_via_popup() function. The popup upload handler lacks file extension and MIME type validation, and uses the raw attacker-supplied filename directly as the destination for move_uploaded_file().
- Affected versions: all versions up to and including 2.9.2
- Attackers: unauthenticated
- Impact: upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory
- Condition: a public quote rule with the multi-page popup flow is enabled
Reference: CVE-2026-18143 on NVD
← Back to Security News