Impact
The WordPress plugin Request a Quote in versions through 2.5.6 contains an unauthenticated AJAX endpoint that fails to perform an authorization check. An attacker can invoke this handler to retrieve the full contact records submitted via the quote request form, even for entries that have not been published. This flaw enables the disclosure of potentially sensitive customer information and can be used by unauthenticated individuals to harvest data from the site.
Affected Systems
Any WordPress site that has the Request a Quote plugin installed at version 2.5.6 or earlier is affected. Because the vendor identifier is unavailable, the flaw applies to all sites that rely on this specific plugin release regardless of the host environment.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog and its EPSS score is currently unknown, indicating no publicly available exploit packages have been documented. Nonetheless, the flaw can be exploited with minimal effort through a direct HTTP request to the unauthenticated AJAX endpoint, requiring no authentication or special privileges. The impact is limited to information disclosure, but the ease of exploitation and lack of mitigations on many installations create a moderate risk for affected sites.
OpenCVE Enrichment