GHSA-h65m-r3wh-mc5jMediumCVSS 6.4
The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site...
🔗 CVE IDs covered (1)
📋 Description
The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A Contributor-level user can trigger execution against higher-privileged users by embedding the malicious shortcode in a post submitted for review, causing the injected scripts to execute when an administrator previews or views the post.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-8884
- https://plugins.trac.wordpress.org/browser/iq-quotation-page/trunk/IQ-quotation-page.php#L339
- https://plugins.trac.wordpress.org/browser/iq-quotation-page/trunk/IQ-quotation-page.php#L429
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f7140053-a3c3-44c4-bc83-2e9b9e8853d6?source=cve
- https://github.com/advisories/GHSA-h65m-r3wh-mc5j