cleantalk
Vulnerabilities and Security Researches

Request a Quote, CVE-2026-90988

CVE, Research URL

CVE-2026-90988

Application

Request a Quote

Published on
Oct 02, 2026
Research Description
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
Affected versions
max 2.5.6.
Status
vulnerable