External risk intelligence

Request a Quote for WooCommerce Arbitrary File Upload Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-18143

The vulnerability exists in a WordPress plugin designed for public-facing e-commerce storefronts. Because the "Request a Quote" functionality is intended for use by external site visitors and the upload handler is accessible without authentication when enabled, this component is intentionally exposed to the public internet.

Unrestricted File Upload

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a WordPress plugin used for quote requests, specifically affecting how uploaded files are handled. This flaw could allow unauthenticated attackers to upload malicious files, potentially leading to unauthorized code execution on affected websites. The primary concern is to determine if this plugin is in use and if the specific vulnerable functionality is enabled.

  • Allows uploading malicious files.
  • Affects public-facing quote requests.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could upload malicious executable files to a web-accessible directory by exploiting a flaw in the Request a Quote for WooCommerce plugin. This occurs when a public quote rule is enabled, allowing the attacker to bypass file validation checks during the popup quote submission process. Successful exploitation could lead to the execution of arbitrary code on the server.

  • No authentication is required.
  • An attacker triggers the vulnerability via the popup upload feature.
  • Risk of arbitrary code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

When a public quote rule with the multi-page popup flow is enabled, unauthenticated attackers could upload executable files to a web-accessible temporary directory. This could impact the integrity and availability of the affected WordPress site.

  • Website files could be compromised.
  • Executable files uploaded via the plugin.
  • Site defacement or full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Request a Quote for WooCommerce plugin affects unauthenticated users who can upload executable files to a web-accessible directory. Platform and security teams should first identify all instances of the plugin, confirm whether they are publicly accessible and critical, and then assign an owner to manage remediation based on risk.

  • Platform and security teams own this issue.
  • Verify plugin reachability and business criticality.
  • Plan vendor-coordinated updates or temporary mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Request a Quote for WooCommerce plugin?

This WordPress plugin allows online store owners to add a quoting system, enabling customers to request pricing for items. It is specifically used in e-commerce storefronts to facilitate B2B or custom pricing workflows. The vulnerable component, the 'Request a Quote' popup feature, is designed to handle document attachments from prospective buyers during these quote submissions.

What is the weakness class for CVE-2026-18143?

This vulnerability is classified as CWE-434, or Unrestricted Upload of File with Dangerous Type. In plain terms, the plugin fails to verify the content or extension of uploaded files. Because the software does not check if an uploaded file is a harmless image or a dangerous script, it allows the server to save and potentially execute unauthorized files provided by a user.

How can an attacker trigger this file upload vulnerability?

An attacker triggers this by using the plugin's popup quote submission form. The flaw is not activated if the specific 'multi-page popup flow' is disabled for your quote rules. It is also not triggered by standard site navigation; the attacker must intentionally interact with the upload handler in a way that sends a malicious file through that specific quote request path.

Is my website at risk from this plugin vulnerability?

According to Halo Surface Signal, this vulnerability is very likely to impact public-facing e-commerce sites. Because the plugin is designed for external customer quote requests, the affected code path is inherently exposed to the internet. If you use this plugin with the multi-page popup flow enabled, your site is reachable by unauthenticated visitors, making it a potential target.

What steps should I take if I use this plugin?

First, inventory your WordPress sites to identify every instance where this plugin is active. Check your plugin settings to see if the multi-page popup quote flow is currently enabled. If it is, consider disabling the feature or the plugin entirely until you can coordinate a secure update. Document your current configuration so you can prioritize remediation based on which storefronts are most accessible to the public.

References