CVE-2024-11034: Wpbean Request A Quote

High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.

The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Affected products

  • Wpbean Request A Quote: up to and including 1.4
  • Wpbean Request A Quote For Woocommerce – Get A Quote Button: up to and including 1.4

Published 2024-11-23. Last modified 2026-06-17.