CRITICAL 9.8 CVE-2026-18143 Published 26 Sept 2026

Request a Quote for WooCommerce Plugin Arbitrary File Upload Vulnerability

Worried this affects your website?

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to and including 2.9.2.

The flaw exists in the afrfq_submit_quote_via_popup() function. The popup upload handler lacks file extension and MIME type validation, and uses the raw attacker-supplied filename directly as the destination for move_uploaded_file().

  • Affected versions: all versions up to and including 2.9.2
  • Attackers: unauthenticated
  • Impact: upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory
  • Condition: a public quote rule with the multi-page popup flow is enabled

Reference: CVE-2026-18143 on NVD

← Back to Security News