CVE-2026-14249
emarket-design Request a Quote – Quote Forms for Any WordPress Site
The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function name from the attacker-controlled $_POST['path'] parameter and invoking it dynamically via the variable-function call $sess_name(), and the handler being registered for wp_ajax_nopriv with its only protection being a nonce that the plugin prints into the public quote-form page via wp_localize_script. This makes it possible for unauthenticated attackers to invoke arbitrary zer...
- CVSS
- 7.5
- EPSS
- 0.33% 25.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.02