← Back to search

CVE-2026-18143

9.8 CRITICAL

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary directory, leading to Remote Code Execution (RCE).
Exploitability
Exploitation is relatively easy as it requires enabling a public quote rule with the multi-page popup flow and uploading a file with a valid filename but an executable payload.
Blast radius
If exploited, the impact could be severe, as it allows attackers to execute arbitrary code on the server, potentially leading to full server compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or upgrade to version 3.0 or later.
rcewebuploadarbitrary-file-upload

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.