CVE-2026-90988
Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
| Vendor | unknown |
| Product | request a quote |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown request a quote
Be the first to know when new unknown vulnerabilities affecting unknown request a quote are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Request a Quote
0 โค 2.5.6
References
Credits
Artus KG WPScan