8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.
Basic Information
ID
CVE-2025-8420
Source
Wordfence
Published
Aug 6, 2025 at 02:24
Modified
Aug 6, 2025 at 13:36
Affected Product
Vendor
emarket-design
Product
Request a Quote Form Plugin – Price Quote Request Management Made Easy
Version
*
Affected Versions
emarket-design Request a Quote Form Plugin – Price Quote Request Management Made Easy *