WordPress Plugin Vulnerabilities
Request a Quote Form Plugin < 2.5.6 - Unauthenticated Limited Remote Code Execution via path Parameter
Description
The plugin does not properly restrict access to an AJAX action that dynamically invokes a PHP function whose name is derived from unauthenticated user input. This makes it possible for unauthenticated attackers to invoke arbitrary zero-argument PHP functions on the server, such as phpinfo(), potentially exposing sensitive server configuration or executing other destructive built-in PHP functions.
Affects Plugins
References
Classification
Type
RCE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mitchell
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-01 (about 21 days ago)
Added
2026-07-01 (about 20 days ago)
Last Updated
2026-07-01 (about 20 days ago)