CVE-2025-64248
- EPSS 0.04%
- Veröffentlicht 16.12.2025 08:12:49
- Zuletzt bearbeitet 20.01.2026 15:18:48
Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3.
CVE-2024-6231
- EPSS 0.19%
- Veröffentlicht 23.07.2024 06:15:11
- Zuletzt bearbeitet 20.05.2025 18:18:04
The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal...
CVE-2022-2239
- EPSS 0.22%
- Veröffentlicht 25.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:36
The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2240
- EPSS 3.35%
- Veröffentlicht 25.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:36
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
CVE-2021-24489
- EPSS 0.29%
- Veröffentlicht 25.10.2021 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:53:10
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
CVE-2021-24420
- EPSS 0.18%
- Veröffentlicht 12.07.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:02
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.