Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in a WordPress plugin used for quote requests, specifically affecting how uploaded files are handled. This flaw could allow unauthenticated attackers to upload malicious files, potentially leading to unauthorized code execution on affected websites. The primary concern is to determine if this plugin is in use and if the specific vulnerable functionality is enabled.
- Allows uploading malicious files.
- Affects public-facing quote requests.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could upload malicious executable files to a web-accessible directory by exploiting a flaw in the Request a Quote for WooCommerce plugin. This occurs when a public quote rule is enabled, allowing the attacker to bypass file validation checks during the popup quote submission process. Successful exploitation could lead to the execution of arbitrary code on the server.
- No authentication is required.
- An attacker triggers the vulnerability via the popup upload feature.
- Risk of arbitrary code execution on the server.
Live Threat
Current exploitation, exposure, and threat context
When a public quote rule with the multi-page popup flow is enabled, unauthenticated attackers could upload executable files to a web-accessible temporary directory. This could impact the integrity and availability of the affected WordPress site.
- Website files could be compromised.
- Executable files uploaded via the plugin.
- Site defacement or full system compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in the Request a Quote for WooCommerce plugin affects unauthenticated users who can upload executable files to a web-accessible directory. Platform and security teams should first identify all instances of the plugin, confirm whether they are publicly accessible and critical, and then assign an owner to manage remediation based on risk.
- Platform and security teams own this issue.
- Verify plugin reachability and business criticality.
- Plan vendor-coordinated updates or temporary mitigations.