CVE Database /
CVE-2024-11034
CVE · High
CVE-2024-11034 — Request a Quote for WooCommerce – Get a Quote Button [get-a-quote-button-for-woocommerce] < 1.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-11034
|
Request a Quote for WooCommerce – Get a Quote Button [get-a-quote-button-for-woocommerce] < 1.5 |
Improper Control of Generation of Code ('Code Injection') |
High
7.3
|
< 1.5
|
1.5 |
2024-11-22 |
—
|
CVE-2024-11034
The Request a Quote for WooCommerce plugin through version 1.4 contains a vulnerability in its fire_contact_form AJAX action that permits unauthenticated attackers to execute arbitrary shortcodes. The flaw stems from insufficient validation of user-supplied input before the do_shortcode function processes it, allowing malicious actors to inject and run any shortcode without authentication. This vulnerability could enable attackers to execute code, access sensitive data, or modify website functionality depending on available shortcodes.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings