VYPR

Dealia – Request a Quote

by WordPress

CVEs (2)

  • CVE-2026-2718MedFeb 19, 2026
    risk 0.42cvss 6.4epss 0.00

    The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attributes in all versions up to, and including, 1.0.8. This is due to the use of `wp_kses()` for output escaping within HTML attribute contexts where…

  • CVE-2026-2504MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple AJAX handlers in all versions up to, and including, 1.0.7. The admin nonce (DEALIA_ADMIN_NONCE) is exposed to all users with…