DIRAS TAKE
Treat this as high priority: public exploit code exists, so any internet-facing site using the plugin's public multi-page popup should be mitigated or disabled immediately.
What is CVE-2026-18143?
An unauthenticated attacker can upload files to sites running the Request a Quote for WooCommerce plugin and potentially place executable payloads on the server, enabling code execution (CVE-2026-18143). The issue affects 2.x branch releases up to and including 2.9.2; exploitation only requires access to the public quote popup flow when a public quote rule is active. The upload handler does not validate filenames, extensions or MIME types before moving uploaded files into a web-accessible temporary directory, allowing malicious files to be stored. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Addify Request a Quote for WooCommerce are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.9.2 and earlier |
Is CVE-2026-18143 being exploited?
Public exploit code is available.
How to fix CVE-2026-18143
- Disable the plugin’s public multi-page popup or any public upload functionality until a vendor fix is available.
- Prevent web access to the plugin’s temporary upload directory via web server rules and remove execute permissions from that folder.
- Harden file handling by restricting write permissions and blocking common executable extensions at the webserver level.
- Watch web and application logs for unexpected file uploads and presence of PHP or other executables in upload directories; apply vendor patches as soon as they are released.
Frequently asked questions
Is CVE-2026-18143 being actively exploited?
Public exploit code for CVE-2026-18143 is available, which increases the chance of active exploitation.
Which Request a Quote for WooCommerce versions are affected by CVE-2026-18143?
Versions in the 2.x branch up to and including 2.9.2 are affected.
Is there a patch for CVE-2026-18143?
No fixed version is listed in the provided data; follow Addify guidance and install updates when a patch is released.
Does CVE-2026-18143 require authentication?
No. The vulnerability allows unauthenticated uploads through the plugin’s public popup handler when the public multi-page popup flow is enabled.
References
- nvd.nist.gov/vuln/detail/CVE-2026-18143
- cve.org/CVERecord?id=CVE-2026-18143
- wordfence.com/threat-intel/vulnerabilities/id/3417ec27-6abf-45c7-945f-6ef456ba1187?source=cve
- woocommerce.com/products/request-a-quote-plugin-for-woocommerce
- All Addify CVEs on CVE Radar
- CVEs published in September 2026