• PoC PUBLIC

CVE-2026-18143: unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce

An unauthenticated attacker can upload files to sites running the Request a Quote for WooCommerce plugin and potentially place executable payloads on the server, enabling code execution (CVE-2026-18143). The issue affects 2.x branch releases up to and including 2.9.2; exploitation only requires access to the public quote popup flow when a public quote rule is active. The upload handler does not validate filenames, extensions or MIME types before moving uploaded files into a web-accessible temporary directory, allowing malicious files to be stored.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00413
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority: public exploit code exists, so any internet-facing site using the plugin's public multi-page popup should be mitigated or disabled immediately.

What is CVE-2026-18143?

An unauthenticated attacker can upload files to sites running the Request a Quote for WooCommerce plugin and potentially place executable payloads on the server, enabling code execution (CVE-2026-18143). The issue affects 2.x branch releases up to and including 2.9.2; exploitation only requires access to the public quote popup flow when a public quote rule is active. The upload handler does not validate filenames, extensions or MIME types before moving uploaded files into a web-accessible temporary directory, allowing malicious files to be stored. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Addify Request a Quote for WooCommerce are affected?

BRANCHAFFECTEDFIXED
2.x2.9.2 and earlier

Is CVE-2026-18143 being exploited?

Public exploit code is available.

How to fix CVE-2026-18143

  1. Disable the plugin’s public multi-page popup or any public upload functionality until a vendor fix is available.
  2. Prevent web access to the plugin’s temporary upload directory via web server rules and remove execute permissions from that folder.
  3. Harden file handling by restricting write permissions and blocking common executable extensions at the webserver level.
  4. Watch web and application logs for unexpected file uploads and presence of PHP or other executables in upload directories; apply vendor patches as soon as they are released.

Frequently asked questions

Is CVE-2026-18143 being actively exploited?

Public exploit code for CVE-2026-18143 is available, which increases the chance of active exploitation.

Which Request a Quote for WooCommerce versions are affected by CVE-2026-18143?

Versions in the 2.x branch up to and including 2.9.2 are affected.

Is there a patch for CVE-2026-18143?

No fixed version is listed in the provided data; follow Addify guidance and install updates when a patch is released.

Does CVE-2026-18143 require authentication?

No. The vulnerability allows unauthenticated uploads through the plugin’s public popup handler when the public multi-page popup flow is enabled.

References