CVE-2024-11034: Wpbean Request A Quote
High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.
The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected products
- Wpbean Request A Quote: up to and including 1.4
- Wpbean Request A Quote For Woocommerce – Get A Quote Button: up to and including 1.4
Published 2024-11-23. Last modified 2026-06-17.