Sceawere
Vulnerability Detail
CVE-2026-90988UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Request a Quote Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 17h ago
- Vendor
- Unknown
- Product
- Request a Quote
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T06:16:42.373Z",
"pubdate": "2026-10-02T06:16:42.373Z",
"executiveSummary": "The Request a Quote WordPress plugin, in versions up to 2.5.6, is affected by an unauthenticated information disclosure vulnerability originating from improper access control in an AJAX handler.\nThis flaw allows unauthorized, remote attackers to access and exfiltrate sensitive contact records associated with quote-request submissions.\nThe vulnerability is classified as an improper authorization issue, which bypasses the intended security boundary protecting private business data.\nThe impact is significant, as attackers can gain access to potentially sensitive user information, including names, emails, and inquiry details, without any form of authentication.\nThere are no specific complex exploitation requirements; the vulnerability is exposed directly over the network through the public-facing WordPress AJAX endpoint, posing a high risk to data confidentiality.",
"technicalDetails": "The vulnerability resides within the plugin's AJAX request handling mechanism. The root cause is the failure to implement appropriate security checks—specifically, the omission of nonce verification or capability checks—within an AJAX action intended for internal use.\nIn WordPress plugin development, AJAX handlers must explicitly verify that the user has the necessary permissions (e.g., using current_user_can()) and validate the request via a security nonce to prevent unauthorized access.\nBy neglecting these checks, the plugin exposes an endpoint that, when queried by an unauthenticated user, defaults to executing the handler logic without validating the requester's identity or authorization level.\nThe attack flow begins when an attacker identifies the specific AJAX action name registered by the plugin. By crafting a standard HTTP GET or POST request to the WordPress admin-ajax.php endpoint and including this action name in the 'action' parameter, the attacker can trigger the vulnerable function.\nUpon receiving this request, the backend server executes the function responsible for retrieving quote-request data from the database. Because the function lacks authorization checks, it proceeds to query and return the requested quote records, even if those records have not been published or were intended only for administrative view.\nThe payload does not require malicious code injection or complex manipulation; the vulnerability is purely a logical flaw in the access control layer of the plugin's API design.\nPost-exploitation, an attacker can enumerate and scrape quote submissions, potentially harvesting personally identifiable information (PII) from site users and customers. This leads to a total compromise of the confidentiality of quote submissions managed by the plugin, facilitating reconnaissance or targeted attacks using the gathered data.\nThe issue affects versions up to and including 2.5.6 and requires immediate intervention to restrict access to the underlying AJAX functionality."
}