Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-18143 — Python PoC that checks and exploits CVE-2026-18143, an unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via the popup AJAX handler. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-18143
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPayload Development
GitHubmurrez/cve-2026-18143

CVE-2026-18143

Python PoC that checks and exploits CVE-2026-18143, an unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via the popup AJAX handler.

16 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-18143 — Request a Quote for WooCommerce (Addify) Arbitrary File Upload

Python 3 PoC for CVE-2026-18143 in Request a Quote for WooCommerce (woocommerce-request-a-quote, Addify / WooCommerce.com).

Description (PoCbit / GitHub)

CVE-2026-18143 — Request a Quote for WooCommerce ≤ 2.9.2 allows unauthenticated arbitrary file upload (CWE-434, CVSS 9.8 Critical) via afrfq_submit_quote_via_popup(). The popup handler calls move_uploaded_file() using the raw client filename without extension or MIME allowlisting, writing into a web-accessible temporary RFQ upload directory. Attackers can upload .php shells when a public quote rule uses the multi-page popup flow. Fixed in > 2.9.2.

PoC page: https://pocbit.org/pocs/cve-2026-18143

PoCbit

Catalog: https://pocbit.org/pocs/

ProductRequest a Quote for WooCommerce (Addify)
Plugin pathwp-content/plugins/woocommerce-request-a-quote/
Affected≤ 2.9.2
AJAXaction=afrfq_submit_quote_via_popup → admin-ajax.php
PrerequisitePopup quote rule enabled on storefront

Usage

pip install -r requirements.txt

python poc.py -u https://shop.example --mode check
python poc.py -u https://shop.example --mode check --upload-probe
python poc.py -u https://shop.example --mode exploit --nonce YOUR_NONCE --verify
python poc.py -u https://shop.example --mode exploit --page /shop/ --verify
python poc.py --list targets.example.txt --mode check -j 15

Nonce is usually in front-end JS (afrfq localized object) on shop/product pages when the quote popup is active.

FOFA

body="/wp-content/plugins/woocommerce-request-a-quote/"
body="afrfq"

Legal

Authorized testing only. --upload-probe / --mode exploit write files to the target.

Download Tool