Skip to main content
Vulnerability Database/CVE-2026-18143

CVE-2026-18143: WooCommerce Quote Plugin RCE Vulnerability

CVE-2026-18143 is a file upload flaw in Request a Quote for WooCommerce plugin that enables unauthenticated attackers to upload malicious PHP files. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-18143 Overview

CVE-2026-18143 is an unauthenticated arbitrary file upload vulnerability in the Request a Quote for WooCommerce plugin for WordPress. The flaw affects all versions up to and including 2.9.2. It resides in the afrfq_submit_quote_via_popup() function, which handles file uploads through the multi-page popup quote flow. The handler fails to validate file extensions or MIME types and passes the raw attacker-supplied filename directly to move_uploaded_file(). Attackers can upload executable files such as PHP scripts to a web-accessible directory when a public quote rule with the popup flow is enabled. This leads to remote code execution on the WordPress host. The vulnerability is classified under [CWE-434: Unrestricted Upload of File with Dangerous Type].

Critical Impact

Unauthenticated attackers can upload and execute arbitrary PHP files, enabling full compromise of the WordPress site and underlying server.

Affected Products

  • Request a Quote for WooCommerce plugin for WordPress
  • All versions up to and including 2.9.2
  • WordPress sites running the plugin with a public quote rule and multi-page popup flow enabled

Discovery Timeline

  • 2026-09-26 - CVE-2026-18143 published to the National Vulnerability Database (NVD)
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-18143

Vulnerability Analysis

The vulnerability resides in the plugin's popup upload handler, afrfq_submit_quote_via_popup(). The function processes files submitted through the multi-page popup quote workflow. It accepts uploaded files from unauthenticated visitors when a public quote rule is active. The handler does not inspect the file extension or MIME type before writing the file to disk. It also uses the attacker-controlled filename as the destination path for PHP's move_uploaded_file() function. An attacker can submit a PHP payload with a .php extension and have it stored in the plugin's RFQ temporary upload directory. Because that directory is web-accessible, the attacker can then request the uploaded script and execute arbitrary code in the context of the web server.

Root Cause

The root cause is missing server-side validation in the popup upload path. The handler neither applies a filename allowlist nor normalizes the destination name. It relies on the client-supplied filename and trusts the uploaded content without content-type or extension checks. This is a textbook [CWE-434] unrestricted file upload condition.

Attack Vector

Exploitation requires no authentication and no user interaction. An attacker sends a crafted multipart HTTP POST request to the plugin's popup quote submission endpoint. The request includes a PHP file as the uploaded attachment. The plugin stores the file at a predictable, web-accessible RFQ upload path using the attacker-chosen name. The attacker then issues an HTTP GET request to that path to trigger PHP execution on the server.

No verified proof-of-concept code is published. Refer to the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2026-18143

Indicators of Compromise

  • Presence of unexpected .php, .phtml, or .phar files inside the plugin's RFQ temporary upload directory under wp-content/
  • Web server access log entries showing POST requests to the popup quote submission endpoint from unauthenticated clients, followed by GET requests to newly created files in the RFQ upload path
  • New WordPress administrator accounts, modified theme or plugin files, or scheduled tasks created shortly after suspicious uploads
  • Outbound network connections from the PHP worker process to unknown hosts following upload activity

Detection Strategies

  • Monitor WordPress upload directories for files with executable extensions written by the web server user
  • Alert on HTTP requests whose referrer or endpoint matches the Request a Quote plugin's popup submission handler and whose payload includes PHP shebangs or <?php tags
  • Correlate file creation events in wp-content/uploads/ with subsequent GET requests to the same filenames to identify webshell execution patterns

Monitoring Recommendations

  • Enable file integrity monitoring on the WordPress document root, with elevated sensitivity for plugin and upload directories
  • Forward web server access logs and PHP error logs to a centralized analytics platform for behavioral review
  • Track process lineage from the PHP-FPM or Apache worker process to detect post-exploitation command execution

How to Mitigate CVE-2026-18143

Immediate Actions Required

  • Update the Request a Quote for WooCommerce plugin to a version released after 2.9.2 that remediates CVE-2026-18143
  • If an update is not yet available, deactivate and remove the plugin from affected WordPress installations
  • Audit the plugin's RFQ upload directory for unexpected files and remove any PHP or other executable artifacts
  • Rotate WordPress administrator credentials and review user accounts for unauthorized additions

Patch Information

Consult the plugin vendor's advisory on the WooCommerce Request for Quote Plugin product page and the Wordfence Vulnerability Report for the fixed version and release notes. Apply the patched release across all WordPress sites that use the plugin.

Workarounds

  • Disable all public quote rules that use the multi-page popup flow until the plugin is patched
  • Configure the web server to deny execution of PHP within wp-content/uploads/ and any plugin-managed upload directories
  • Place a web application firewall rule in front of the plugin's popup submission endpoint to block requests containing executable file extensions
bash
# Apache: block PHP execution inside WordPress uploads directory
<Directory "/var/www/html/wp-content/uploads">
    <FilesMatch "\.(php|phtml|phar|php[0-9]+)$">
        Require all denied
    </FilesMatch>
</Directory>

# Nginx equivalent
location ~* /wp-content/uploads/.*\.(php|phtml|phar|php[0-9]+)$ {
    deny all;
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.