If you run a WooCommerce store with Addify's Request a Quote for WooCommerce plugin, a stranger with no account may be able to drop a PHP file onto your server and run it. That is the practical meaning of CVE-2026-18143, a critical unauthenticated arbitrary file upload rated 9.8 out of 10. The detail that turns this from urgent into a scramble: as of publication there is no fixed release. The version listed as current on the official WooCommerce marketplace, 2.9.2, is the one that carries the bug.
Wordfence, which assigned the CVE, classifies it as CWE-434, an unrestricted upload of a file with a dangerous type. Its severity metrics tell the story: reachable straight over the network, low attack complexity, and neither a login nor any user interaction needed, with full impact to confidentiality, integrity, and availability.
What the flaw actually is
The problem sits in the plugin function afrfq_submit_quote_via_popup(), the handler behind the multi-page popup that lets shoppers attach a file to a quote request. According to Wordfence, that handler skips the checks that should decide whether an upload is allowed. It does not validate the file extension, it does not validate the MIME type, and it feeds the filename the visitor supplied straight into PHP's move_uploaded_file() as the destination path.
Strip away the jargon and the sequence is short. An attacker sends a request that would normally attach an innocent document to a quote. Instead they send a .php file. Because nothing rejects it, the file lands in a web-reachable upload directory under the name the attacker chose. They then request that file in a browser, the server executes it as code, and the attacker has a foothold. Arbitrary file upload of an executable type is one of the most direct paths to remote code execution there is, which is why the score sits at the top of the scale.
Who is actually exposed
Two things scope this, and both matter for how you triage it.
First, the vulnerable route is live only where a store turns on an anonymous public quote rule that drives the multi-step popup upload. That is a normal setup for a business-to-business store that wants anonymous visitors to request quotes, but it is not every install. If your quote form is gated behind a login, or you do not use the popup flow, the exposure is smaller. Check your configuration before you assume you are safe, and before you assume you are hit.
Second, adoption. This is a paid plugin sold on the official WooCommerce marketplace, where the listing reports more than 5,000 active installations and a 4.7 rating across 161 reviews. That is a smaller footprint than a free directory plugin, but every one of those installs is a real commerce site handling customer and order data, which is exactly the kind of target that gets swept for a fresh critical.
On exploitation: at the time of writing we found no public proof-of-concept code, no listing in the CISA Known Exploited Vulnerabilities catalog, and no reports of exploitation in the wild. Read that as a head start, not as comfort. Unauthenticated file-upload bugs in WordPress add-ons are among the fastest to be weaponized once the details circulate, and the window between a Wordfence disclosure and opportunistic scanning is usually measured in hours to days. This is the latest in a run of unauthenticated file-handling flaws in WooCommerce add-ons; we covered a file-inclusion bug in the HUSKY Products Filter plugin days ago.
What to do before a patch exists
Updating is normally step one, and here you cannot: there is no fixed version to install yet. So the job today is to close the path and watch for abuse.
- Turn off the public quote rule that uses the multi-page popup, or restrict quote submission to logged-in users, until Addify ships a fix. Removing the reachable configuration removes the exposure.
- Deny execution of PHP inside your uploads tree as defense in depth. A store's uploads directory should never run code, and this one server-side rule neutralizes a planted webshell even if a file lands.
- Hunt now. Search your web server access logs for POST requests to
admin-ajax.phpthat call the quote popup action, and look for recently created.phpfiles anywhere underwp-content/uploads. A new script in a folder that should only hold images or documents is the tell. - Watch the plugin's marketplace page and Addify's channels for the patched release, and apply it the moment it lands.
# Apache / LiteSpeed - save as wp-content/uploads/.htaccess <FilesMatch "\.(?:php|phtml|php[0-9]|phps)$"> Require all denied </FilesMatch> # nginx - add inside the site server block location ~* ^/wp-content/uploads/.*\.php$ { deny all; return 403; }
The file that appears where it should not is the observable worth alerting on. A new executable dropped into a web root is precisely the change a file-integrity monitor is built to catch, and Suriq, which runs on Wazuh, watches exactly that kind of unexpected write. Detection buys you time that a missing patch does not.
The short version
CVE-2026-18143 is a critical, unauthenticated route to code execution on WooCommerce stores running Request a Quote for WooCommerce through 2.9.2, with no fix available yet. If you run the plugin with a public popup quote form, treat this as live work: disable the path, block PHP execution in uploads, and check your logs and upload folders now.