WordPress Plugin Vulnerabilities

Request a Quote Form Plugin < 2.5.6 - Unauthenticated Limited Remote Code Execution via path Parameter

Description

The plugin does not properly restrict access to an AJAX action that dynamically invokes a PHP function whose name is derived from unauthenticated user input. This makes it possible for unauthenticated attackers to invoke arbitrary zero-argument PHP functions on the server, such as phpinfo(), potentially exposing sensitive server configuration or executing other destructive built-in PHP functions.

Affects Plugins

Fixed in 2.5.6

References

Classification

Type
RCE
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Mitchell
Verified
No

Timeline

Publicly Published
2026-07-01 (about 21 days ago)
Added
2026-07-01 (about 20 days ago)
Last Updated
2026-07-01 (about 20 days ago)

Other