CVE-2026-90988: Unknown Request A Quote

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.

Affected products

  • Unknown Request A Quote: up to and including 2.5.6

Published 2026-10-02. Last modified 2026-10-02.