CVE 8.1 HIGH

Request a Quote Form Plugin <= 2.5.2 - Unauthenticated Limited Remote Code Execution_CVE-2025-8420

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

Basic Information

ID CVE-2025-8420
Source Wordfence
Published Aug 6, 2025 at 02:24
Modified Aug 6, 2025 at 13:36

Affected Product

Vendor emarket-design
Product Request a Quote Form Plugin – Price Quote Request Management Made Easy
Version *
Affected Versions emarket-design Request a Quote Form Plugin – Price Quote Request Management Made Easy *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.