Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
high
The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function name from the attacker-controlled $_POST['path'] parameter and invoking it dynamically via the variab...
- CVSS:
- 7.5
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Jul 1, 2026
CVE-2026-14249 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] <= 2.5.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3.
- Affected:
- up to 2.5.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-64248 on NVD →
Request a Quote <= 2.5.3 - Missing Authorization
medium
The Request a Quote Form Plugin – Price Quote Request Management Made Easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Dec 15, 2025
CVE-2025-64248 on NVD →
Multiple Plugins by eMarket Design <= Various Versions - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
Multiple plugins for WordPress by by eMarket Design are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Sep 23, 2025
CVE-2025-58915 on NVD →
Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code Execution
high
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible fo...
- CVSS:
- 8.1
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Aug 5, 2025
CVE-2025-8420 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.4.1
unknown
[en] The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 23, 2024
CVE-2024-6231 on NVD →
Request a Quote <= 2.4.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...
- CVSS:
- 4.4
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 2, 2024
CVE-2024-6231 on NVD →
Request a Quote <= 2.3.10 - Cross-Site Request Forgery
medium
The Request a Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.10. This is due to missing nonce validation on the emd_show_forms_lite_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request gra...
- CVSS:
- 4.3
- Affected:
- up to 2.3.11
- Fixed in:
- 2.3.11
- Disclosed:
- Jun 30, 2023
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.3.11
unknown
Update the WordPress Request a Quote plugin to the latest available version (at least 2.3.11).
An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Request a Quote Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actio...
- Affected:
- up to 2.3.11
- Fixed in:
- 2.3.11
- Disclosed:
- Jun 30, 2023
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.3.11
unknown
The Request a Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.10. This is due to missing nonce validation on the emd_show_forms_lite_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request gra...
- Affected:
- up to 2.3.11
- Fixed in:
- 2.3.11
- Disclosed:
- Jun 30, 2023
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.3.9
unknown
[en] The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 2.3.9
- Fixed in:
- 2.3.9
- Disclosed:
- Jul 25, 2022
CVE-2022-2239 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.3.8
unknown
[en] The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Jul 25, 2022
CVE-2022-2240 on NVD →
Request a Quote <= 2.3.8 - CSV Injection
high
The Request a Quote WordPress plugin through 2.3.8 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
- CVSS:
- 8.3
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.9
- Disclosed:
- Jun 28, 2022
CVE-2022-2240 on NVD →
Request a Quote <= 2.3.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Request a Quote WordPress plugin through 2.3.7 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Jun 28, 2022
CVE-2022-2239 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] <= 2.3.7
unknown
CSV Injection vulnerability discovered by Benachi in WordPress Request a Quote plugin (versions <= 2.3.7).
Deactivate and delete. This plugin has been closed as of June 21, 2022 and is not available for download. This closure is temporary, pending a full review.
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
- Disclosed:
- Jun 28, 2022
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] <= 2.3.7
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Benachi in WordPress Request a Quote plugin (versions <= 2.3.7).
Deactivate and delete. This plugin has been closed as of June 21, 2022 and is not available for download. This closure is temporary, pending a full review.
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
- Disclosed:
- Jun 28, 2022
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.3.9
unknown
[en] The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
- Affected:
- up to 2.3.9
- Fixed in:
- 2.3.9
- Disclosed:
- Oct 25, 2021
CVE-2021-24489 on NVD →
Request a Quote <= 2.3.4 - Stored Cross-Site Scripting
medium
The Request a Quote WordPress plugin before 2.3.5 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Sep 21, 2021
CVE-2021-24489 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.3.4
unknown
[en] The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Jul 12, 2021
CVE-2021-24420 on NVD →
Request a Quote <= 2.3.3 - Authenticated Stored Cross-Site Scripting
medium
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.
- CVSS:
- 5.4
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Jun 16, 2021
CVE-2021-24420 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.5.3
unknown
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
CVE-2025-8420 on NVD →
Request a Quote Form Plugin – Price Quote Request Management Made Easy [request-a-quote] < 2.5.1
unknown
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
CVE-2025-58915 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database