plugin

Dealia Request A Quote Vulnerabilities

2 known security issues reported for the Dealia Request A Quote WordPress plugin. Most recent disclosed Feb 18, 2026.

2 medium

Running Dealia Request A Quote on your site? Check whether your installed version is affected.

Scan your site free

Dealia <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block Attributes

medium

The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attributes in all versions up to, and including, 1.0.8. This is due to the use of `wp_kses()` for output escaping within HTML attribute contexts where `esc_attr()` is required. This makes it possible for a...

CVSS:
6.4
Affected:
up to 1.0.8
Fix:
No patched version reported
Disclosed:
Feb 18, 2026

CVE-2026-2718 on NVD →

Dealia – Request a quote <= 1.0.7 - Missing Authorization to Authenticated (Contributor+) Plugin Configuration Reset

medium

The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple AJAX handlers in all versions up to, and including, 1.0.7. The admin nonce (DEALIA_ADMIN_NONCE) is exposed to all users with edit_posts capability (Contributor+) via wp_local...

CVSS:
4.3
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Feb 18, 2026

CVE-2026-2504 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database