Skip to finding
important · WooCommerce — RCE

Addify’s public quote popup can upload and run PHP without authentication.

Affects

Addify Request a Quote for WooCommerce, a commercial WordPress/WooCommerce quotation plugin installed on online stores.

A store is exposed only when it has an unauthenticated quote rule using the multi-page popup. The AJAX handler then preserves an attacker’s PHP filename and writes the file into a web-accessible RFQ directory without extension or MIME validation.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026