Home/ Blog/ Security news/ Article
Blog · Security news

Request a Quote WooCommerce CVE-2026-18143: Unauth RCE, No Patch

CVE-2026-18143 is a critical unauthenticated file-upload flaw in Request a Quote for WooCommerce (through 2.9.2), with no patch yet. Act now.

An unlatched shipping crate on an industrial loading dock under cool light

If you run a WooCommerce store with Addify's Request a Quote for WooCommerce plugin, a stranger with no account may be able to drop a PHP file onto your server and run it. That is the practical meaning of CVE-2026-18143, a critical unauthenticated arbitrary file upload rated 9.8 out of 10. The detail that turns this from urgent into a scramble: as of publication there is no fixed release. The version listed as current on the official WooCommerce marketplace, 2.9.2, is the one that carries the bug.

Wordfence, which assigned the CVE, classifies it as CWE-434, an unrestricted upload of a file with a dangerous type. Its severity metrics tell the story: reachable straight over the network, low attack complexity, and neither a login nor any user interaction needed, with full impact to confidentiality, integrity, and availability.

What the flaw actually is

The problem sits in the plugin function afrfq_submit_quote_via_popup(), the handler behind the multi-page popup that lets shoppers attach a file to a quote request. According to Wordfence, that handler skips the checks that should decide whether an upload is allowed. It does not validate the file extension, it does not validate the MIME type, and it feeds the filename the visitor supplied straight into PHP's move_uploaded_file() as the destination path.

Strip away the jargon and the sequence is short. An attacker sends a request that would normally attach an innocent document to a quote. Instead they send a .php file. Because nothing rejects it, the file lands in a web-reachable upload directory under the name the attacker chose. They then request that file in a browser, the server executes it as code, and the attacker has a foothold. Arbitrary file upload of an executable type is one of the most direct paths to remote code execution there is, which is why the score sits at the top of the scale.

Who is actually exposed

Two things scope this, and both matter for how you triage it.

First, the vulnerable route is live only where a store turns on an anonymous public quote rule that drives the multi-step popup upload. That is a normal setup for a business-to-business store that wants anonymous visitors to request quotes, but it is not every install. If your quote form is gated behind a login, or you do not use the popup flow, the exposure is smaller. Check your configuration before you assume you are safe, and before you assume you are hit.

Second, adoption. This is a paid plugin sold on the official WooCommerce marketplace, where the listing reports more than 5,000 active installations and a 4.7 rating across 161 reviews. That is a smaller footprint than a free directory plugin, but every one of those installs is a real commerce site handling customer and order data, which is exactly the kind of target that gets swept for a fresh critical.

On exploitation: at the time of writing we found no public proof-of-concept code, no listing in the CISA Known Exploited Vulnerabilities catalog, and no reports of exploitation in the wild. Read that as a head start, not as comfort. Unauthenticated file-upload bugs in WordPress add-ons are among the fastest to be weaponized once the details circulate, and the window between a Wordfence disclosure and opportunistic scanning is usually measured in hours to days. This is the latest in a run of unauthenticated file-handling flaws in WooCommerce add-ons; we covered a file-inclusion bug in the HUSKY Products Filter plugin days ago.

What to do before a patch exists

Updating is normally step one, and here you cannot: there is no fixed version to install yet. So the job today is to close the path and watch for abuse.

  1. Turn off the public quote rule that uses the multi-page popup, or restrict quote submission to logged-in users, until Addify ships a fix. Removing the reachable configuration removes the exposure.
  2. Deny execution of PHP inside your uploads tree as defense in depth. A store's uploads directory should never run code, and this one server-side rule neutralizes a planted webshell even if a file lands.
  3. Hunt now. Search your web server access logs for POST requests to admin-ajax.php that call the quote popup action, and look for recently created .php files anywhere under wp-content/uploads. A new script in a folder that should only hold images or documents is the tell.
  4. Watch the plugin's marketplace page and Addify's channels for the patched release, and apply it the moment it lands.
Deny PHP execution under wp-content/uploads (Apache/LiteSpeed .htaccess, and nginx)
# Apache / LiteSpeed - save as wp-content/uploads/.htaccess
<FilesMatch "\.(?:php|phtml|php[0-9]|phps)$">
    Require all denied
</FilesMatch>
# nginx - add inside the site server block
location ~* ^/wp-content/uploads/.*\.php$ {
    deny all;
    return 403;
}

The file that appears where it should not is the observable worth alerting on. A new executable dropped into a web root is precisely the change a file-integrity monitor is built to catch, and Suriq, which runs on Wazuh, watches exactly that kind of unexpected write. Detection buys you time that a missing patch does not.

The short version

CVE-2026-18143 is a critical, unauthenticated route to code execution on WooCommerce stores running Request a Quote for WooCommerce through 2.9.2, with no fix available yet. If you run the plugin with a public popup quote form, treat this as live work: disable the path, block PHP execution in uploads, and check your logs and upload folders now.

Topics

Frequently asked questions

What is CVE-2026-18143?

CVE-2026-18143 is a critical unauthenticated arbitrary file upload vulnerability in the Request a Quote for WooCommerce plugin by Addify, affecting all versions up to and including 2.9.2. Wordfence, which assigned the CVE, rates it 9.8 out of 10 and classifies it as CWE-434. An attacker with no account can upload an executable PHP file and have the server run it.

Is there a patch available?

Not at the time of writing. The affected range covers every release through 2.9.2, and 2.9.2 is the version listed as current on the official WooCommerce marketplace, so there is no fixed release to install yet. Until Addify ships one, disable the public popup quote flow and block PHP execution in your uploads directory.

Which stores are actually exposed?

The reachable path opens only when a public quote rule using the multi-page popup upload flow is enabled, which is a common setup for business-to-business stores that accept quote requests from anonymous visitors. If quote submission requires a login or you do not use the popup flow, the exposure is smaller. Confirm your configuration rather than assuming.

Is it being exploited in the wild?

We found no public proof-of-concept code, no CISA Known Exploited Vulnerabilities listing, and no reports of in-the-wild exploitation at disclosure. That is a head start, not safety: unauthenticated file-upload flaws in WordPress plugins are typically scanned for and weaponized within hours to days of a Wordfence advisory.

How do I check whether my store was hit?

Search your web server access logs for POST requests to admin-ajax.php that call the quote popup action, then look for recently created .php files anywhere under wp-content/uploads. A new script in a folder that should hold only images or documents is the clearest sign someone planted a webshell.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.