CVE · High

CVE-2024-11034 — Request a Quote for WooCommerce – Get a Quote Button [get-a-quote-button-for-woocommerce] < 1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11034 Request a Quote for WooCommerce – Get a Quote Button [get-a-quote-button-for-woocommerce] < 1.5 Improper Control of Generation of Code ('Code Injection') High 7.3 < 1.5 1.5 2024-11-22

CVE-2024-11034

The Request a Quote for WooCommerce plugin through version 1.4 contains a vulnerability in its fire_contact_form AJAX action that permits unauthenticated attackers to execute arbitrary shortcodes. The flaw stems from insufficient validation of user-supplied input before the do_shortcode function processes it, allowing malicious actors to inject and run any shortcode without authentication. This vulnerability could enable attackers to execute code, access sensitive data, or modify website functionality depending on available shortcodes.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.