Unrated severityNVD Advisory· Published Oct 2, 2026
CVE-2026-90988
CVE-2026-90988
Description
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.5.6
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.