CVE-2026-14962
ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database.
| Vendor | unknown |
| Product | elex woocommerce request a quote |
| Published | Sep 9, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown elex woocommerce request a quote
Be the first to know when new high vulnerabilities affecting unknown elex woocommerce request a quote are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / ELEX WooCommerce Request a Quote
0 < 2.4.1
References
Credits
Artus KG WPScan