Skip to main content

Threat intelligence

Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter

CVE-2026-14249 · request-a-quote

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Request A Quote at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
Affected software
request-a-quote(Plugin)
Affected versions
  • ≤ 2.5.5
Authentication
Unauthenticated
Vulnerability type
Other
Published
1 July 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 5a349c4f-d2e7-47af-9013-3cfa496b3b8c). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Request A Quote version against this catalog when the Defence plugin is connected to your WordPress site.