{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/addify/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:request_a_quote_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18143"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=B13EF2AE-C623-5E73-84DC-128E88C26890\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Request a Quote for WooCommerce (\u003c= 2.9.2)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","arbitrary-file-upload","remote-code-execution","cve-2026-18143"],"_cs_type":"advisory","_cs_vendors":["WordPress","Addify","WooCommerce"],"content_html":"\u003cp\u003eThe Request a Quote for WooCommerce plugin for WordPress is vulnerable to an arbitrary file upload flaw, assigned as CVE-2026-18143, affecting all versions up to and including 2.9.2. The vulnerability exists within the afrfq_submit_quote_via_popup() function, which fails to perform server-side validation on file extensions or MIME types during the file upload process. When a site has a public quote rule configured to use the multi-page popup flow, an unauthenticated attacker can supply a malicious PHP file through the request handler. The plugin uses the attacker-provided filename directly when calling move_uploaded_file(), writing the file to a web-accessible temporary directory. Successful exploitation allows an attacker to execute arbitrary code on the underlying web server, posing a critical threat to the integrity and confidentiality of the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18143 enables unauthenticated remote code execution on WordPress sites running the vulnerable plugin version. This grants attackers the ability to compromise site data, escalate privileges within the WordPress environment, or gain persistent access to the host server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Request a Quote for WooCommerce plugin to the version containing the patch for CVE-2026-18143.\u003c/li\u003e\n\u003cli\u003eImplement a web application firewall (WAF) rule to block POST requests containing executable extensions (e.g., .php, .phtml) directed toward the plugin's quote upload endpoint.\u003c/li\u003e\n\u003cli\u003eAudit the temporary upload directory for unauthorized scripts if the plugin was previously exposed to the internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T09:38:12Z","date_published":"2026-09-26T08:57:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18143/","summary":"The Request a Quote for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions 2.9.2 and below, allowing remote attackers to upload executable PHP files.","title":"Arbitrary File Upload Vulnerability in Request a Quote for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18143/"}],"language":"en","title":"CraftedSignal Threat Feed - Addify","version":"https://jsonfeed.org/version/1.1"}