{"id":"CVE-2026-18143","published":"2026-09-26T07:17:02.017","lastModified":"2026-09-28T15:16:04.793","description":"The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://woocommerce.com/products/request-a-quote-plugin-for-woocommerce/","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3417ec27-6abf-45c7-945f-6ef456ba1187?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary directory, leading to Remote Code Execution (RCE).","exploitability":"Exploitation is relatively easy as it requires enabling a public quote rule with the multi-page popup flow and uploading a file with a valid filename but an executable payload.","blast_radius":"If exploited, the impact could be severe, as it allows attackers to execute arbitrary code on the server, potentially leading to full server compromise.","remediation":"Disable the affected feature or upgrade to version 3.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","upload","arbitrary-file-upload"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:53:11.770Z"}}