CVE-2025-8420 – WordPress Request a Quote Form Plugin Remote Code Execution Vulnerability

CVE ID : CVE-2025-8420

Published : Aug. 6, 2025, 3:15 a.m. | 18 minutes ago

Description : The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share the Post:

Related Posts