Skip to main content

[Critical] Addify Request a Quote for WooCommerce Unauthenticated File Upload (CVE-2026-18143)

A vulnerability published on 26 September 2026 in Addify’s Request a Quote for WooCommerce plugin allows any visitor, without logging in, to upload a file of their choosing through the plugin’s quote pop-up form. The form handler does not check the type or extension of uploaded files, so an attacker can upload a PHP script and then run it on the server. The issue was reported by the researcher t4g0 and published through Wordfence. At the time of writing, no fixed version had been documented. The plugin is sold through the WooCommerce marketplace rather than WordPress.org, which means it may not update automatically in the way many free plugins do.

Affected:

Request a Quote for WooCommerce (Addify), versions up to and including 2.9.2.

Fixed version:

None documented at the time of writing.

CVSS:

9.8 (Critical).

What This Means For You:

The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we are covering three issues: an unpatched file upload flaw in a WooCommerce quote plugin, a critical code execution issue in the widely used Drupal Webform module, and a cPanel flaw that lets any hosting account run code as root. The common thread is that each one can be reached from a website or a hosting account that looks entirely ordinary, so keeping software up to date remains the most effective defence.

Shared hosting: On shared hosting, a successful attack gives the attacker control of the affected WordPress site and everything stored in that hosting account, including order and contact details held in the shop.

VPS and dedicated servers: On a VPS or dedicated server, the attacker gains code execution as the web server user, which can be used as a starting point to attack the rest of the server.

Recommended Action:

If this plugin is installed, deactivate it until a fixed version is released and check its upload folder for unexpected .php files. Where the quote feature is essential, ask your developer to block PHP execution in the plugin’s upload directory as a temporary measure.

[Critical] Drupal Webform Remote Code Execution (CVE-2026-96355, SA-CONTRIB-2026-175)

On 23 September 2026, the Drupal Security Team published 22 coordinated advisories for Webform, one of the most widely used Drupal modules for building forms. The most serious, SA-CONTRIB-2026-175, affects forms that use a custom format for fields that accept multiple values. Webform did not exclude those formats from token replacement, so text submitted by a visitor could be treated as template code when the submission was displayed. Depending on the site’s configuration and other enabled modules, this can lead to information disclosure, stored cross-site scripting or remote code execution. The Drupal Security Team rates exploitation as theoretical and the affected configuration as uncommon, but the same release also fixes several access bypass and cross-site scripting issues that affect more sites.

Affected:

Webform 6.2.x before 6.2.12 and 6.3.x before 6.3.1.

Fixed version:

6.2.12 and 6.3.1.

CVSS:

Rated Critical by the Drupal Security Team (Drupal risk scoring, not CVSS).

What This Means For You:

Shared hosting: On shared hosting, a site that uses the affected form configuration could have its content, submissions and files exposed or changed by an anonymous visitor.

VPS and dedicated servers: On a VPS or dedicated server the same applies, and code execution would run as the web server user, which may give access to other sites hosted on the same server.

Recommended Action:

Update Webform to 6.2.12 or 6.3.1 on every Drupal site, even if you do not use custom multiple-value formats, as the release fixes 22 separate issues.

[Critical] cPanel CalDAV and CardDAV Root Code Execution (CVE-2026-87899)

cPanel disclosed on 22 September 2026 that its CalDAV and CardDAV service, which stores each account’s calendars and contacts, fails to sanitise input passed to a privileged task. As a result, any logged-in cPanel account holder can run code as root and take full control of the server. cPanel lists no requirement other than having an account. The same release fixes a related flaw (CVE-2026-68490) that lets a local user read other accounts’ calendars and contacts, and a WP Toolkit issue (CVE-2026-87900) that lets one cPanel user change databases belonging to other accounts. All three were reported by researcher Ali Mustafa (rz1027), who has been credited with at least seven cPanel and Plesk flaws since late August.

Affected:

cPanel & WHM version 120 and later.

Fixed version:

11.134.0.57, 11.136.0.41, 11.138.0.8 or later, and WP Squared 11.138.1.11 or later. WP Toolkit 6.11.3 or later for CVE-2026-87900.

CVSS:

Not published by cPanel at the time of writing; cPanel describes the impact as full control of the server.

What This Means For You:

Shared hosting: On shared hosting, this is the most serious kind of flaw, because any one account on a server, or anyone who has stolen that account’s password, could take over the whole server and every website on it.

VPS and dedicated servers: On a VPS or dedicated server where you are the only cPanel user, the risk is lower, but a compromised account password or a compromised site could still be turned into full root access.

Recommended Action:

Make sure cPanel & WHM is on a fixed build (run /usr/local/cpanel/scripts/upcp –force if automatic updates are off) and update WP Toolkit to 6.11.3 or later. There is no temporary workaround, so updating is the only fix.

[Critical] WordPress "Login with QR" Plugin Unauthenticated Admin Takeover (CVE-2026-86710)

A vulnerability disclosed on 17 September 2026 in the WordPress plugin “Login with QR” (versions up to and including 1.0.0) allows any unauthenticated visitor to log in as any user on the site, including administrators. The plugin is meant to let a user log in by scanning a QR code, but it fails to verify that the code presented is one it actually issued, instead accepting any code that matches a stored value, which an attacker can guess or generate themselves. No fixed version has been published yet.

How to Check If Your Site Has Been Compromised

  • Review the WordPress or Drupal administrator user list for accounts you do not recognise, particularly any created or given extra permissions in the last week.
  • Look for new or recently changed .php files in your uploads folders and in plugin, theme and module folders.
  • Check your website access logs for repeated or unusual form submissions to quote, booking or upload handlers.
  • Check for unfamiliar cron jobs or scheduled tasks in your hosting account or on your server.
  • Look for outbound connections to unfamiliar IP addresses or domains, or unexpected spikes in resource use.
  • If you find anything suspicious, change all passwords and API keys, restore from a known clean backup where possible, and contact our support team.

Frequently Asked Questions

I keep WordPress itself up to date. Does that protect me from the Addify plugin flaw?

No. Plugin flaws are separate from WordPress core, and premium plugins bought outside WordPress.org often need updating individually. It is worth checking your installed plugins list regularly, not just the WordPress version.

How urgently should I act on these issues?

The Addify plugin flaw needs no account and has no fix yet, so it should be dealt with straight away if you use that plugin. The cPanel flaw is equally urgent for anyone managing their own cPanel server. The Drupal Webform issue should be addressed promptly, as the release fixes 22 separate problems.

What if the plugin I rely on has no fix yet?

Where no fixed version exists, as with the Addify Request a Quote plugin, the safest option is to deactivate the plugin until the developer releases an update. If the feature is essential, speak to your developer about temporary protections such as blocking PHP execution in upload folders.

Does the cPanel flaw affect my website if I am on shared hosting?

The cPanel flaw affects the server rather than an individual website, so it is addressed by updating cPanel & WHM on the server itself. If you manage your own cPanel server, you should confirm it is on a fixed build.

I use Drupal but not custom multiple-value formats in Webform. Do I still need to update?

Yes. The Webform release fixes 22 separate issues, several of which affect common configurations, so updating to 6.2.12 or 6.3.1 is recommended for every site that uses the module.

Summary

Vulnerability CVE CVSS Affected Fixed Action
Addify Request a Quote for WooCommerce file upload CVE-2026-18143 9.8 <= 2.9.2 None yet Deactivate plugin
Drupal Webform remote code execution CVE-2026-96355 Critical (Drupal) 6.2.x < 6.2.12, 6.3.x < 6.3.1 6.2.12 / 6.3.1 Update Webform
cPanel CalDAV/CardDAV root code execution CVE-2026-87899 Not published cPanel & WHM 120+ 11.134.0.57 / 11.136.0.41 / 11.138.0.8 Update cPanel & WHM

Need Help? Get in Touch

If you have any questions about these issues or need help checking your account, please raise a support ticket via the Customer Area at heartinternet.uk, or use live chat, available Monday to Friday, 09:30 to 16:00. You can also find more guidance in our knowledge base at heartinternet.uk/support. We are here to help if you are not sure whether any of this affects you.

Si

Leave a Reply