Emarketdesign

Request A Quote

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 16.12.2025 08:12:49
  • Zuletzt bearbeitet 20.01.2026 15:18:48

Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 23.07.2024 06:15:11
  • Zuletzt bearbeitet 20.05.2025 18:18:04

The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 25.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:36

The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Exploit
  • EPSS 3.35%
  • Veröffentlicht 25.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:36

The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it

Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.10.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:53:10

The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 12.07.2021 20:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:02

The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.