SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14962

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The ELEX WooCommerce Request a Quote plugin for WordPress versions prior to 2.4.1 is vulnerable to SQL injection due to insufficient sanitization and escaping of user-supplied parameters in SQL queries. This flaw allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to unauthorized data extraction from the database. WordPress site administrators using this plugin should prioritize updating to version 2.4.1 or later to mitigate this risk.

CVE
CVE-2026-14962
Severity
HIGH
CVSS
8.6
EPSS
0.32%
WordPress

Original NVD Description

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database.