important · WooCommerce — RCE
Addify’s public quote popup can upload and run PHP without authentication.
Affects
Addify Request a Quote for WooCommerce, a commercial WordPress/WooCommerce quotation plugin installed on online stores.
A store is exposed only when it has an unauthenticated quote rule using the multi-page popup. The AJAX handler then preserves an attacker’s PHP filename and writes the file into a web-accessible RFQ directory without extension or MIME validation.
Detail and 3 sources
A public repository includes both detection and exploit modes for the affected route and configuration.