CVE-2026-90988: Unknown Request A Quote
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
Affected products
- Unknown Request A Quote: up to and including 2.5.6
Published 2026-10-02. Last modified 2026-10-02.