SQL Injection Vulnerability in ELEX WooCommerce Request a Quote Plugin by ELEX
CVE-2026-14962
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-14962?
The ELEX WooCommerce Request a Quote plugin before version 2.4.1 contains a vulnerability that arises from improper sanitization and escaping of parameters in an SQL query. This flaw allows unauthenticated attackers to execute SQL injection attacks, potentially gaining unauthorized access to sensitive data stored in the database. It is crucial for users of this plugin to upgrade to the latest version to mitigate the risk of exploitation.
Affected Version(s)
ELEX WooCommerce Request a Quote 0 < 2.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved