medium · CVSS v3 5.3
CVE-2026-90988
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated…
Description
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —