
Python-PoC, der CVE-2026-18143 prüft und ausnutzt, eine unauthentifizierte beliebige Dateiupload-Schwachstelle in Addify Request a Quote for WooCommerce ≤ 2.9.2 über den Popup-AJAX-Handler.
Python-3-PoC für CVE-2026-18143 in Request a Quote for WooCommerce (woocommerce-request-a-quote, Addify / WooCommerce.com).
CVE-2026-18143 — Request a Quote for WooCommerce ≤ 2.9.2 ermöglicht unauthentifizierten beliebigen Datei-Upload (CWE-434, CVSS 9.8 Critical) über afrfq_submit_quote_via_popup(). Der Popup-Handler ruft move_uploaded_file() mit dem rohen Client-Dateinamen ohne Erweiterungs- oder MIME-Allowlisting auf und schreibt in ein web-erreichbares temporäres RFQ-Upload-Verzeichnis. Angreifer können .php-Shells hochladen, wenn eine öffentliche Quote-Regel den mehrseitigen Popup-Ablauf verwendet. Behoben in > 2.9.2.
PoC-Seite: https://pocbit.org/pocs/cve-2026-18143
Katalog: https://pocbit.org/pocs/
| Produkt | Request a Quote for WooCommerce (Addify) |
| Plugin-Pfad | wp-content/plugins/woocommerce-request-a-quote/ |
| Betroffen | ≤ 2.9.2 |
| AJAX | action=afrfq_submit_quote_via_popup → admin-ajax.php |
| Voraussetzung | Popup-Quote-Regel im Storefront aktiviert |
pip install -r requirements.txt
python poc.py -u https://shop.example --mode check
python poc.py -u https://shop.example --mode check --upload-probe
python poc.py -u https://shop.example --mode exploit --nonce YOUR_NONCE --verify
python poc.py -u https://shop.example --mode exploit --page /shop/ --verify
python poc.py --list targets.example.txt --mode check -j 15
Der Nonce befindet sich üblicherweise im Frontend-JS (lokalisiertes afrfq-Objekt) auf Shop-/Produktseiten, wenn das Quote-Popup aktiv ist.
body="/wp-content/plugins/woocommerce-request-a-quote/"
body="afrfq"
Nur autorisiertes Testen. --upload-probe / --mode exploit schreiben Dateien auf das Ziel.