Medium 4.3
2025-12-16< 2.5.4
CVE-2025-64248
Minimum safe version
2.5.4
Update to 2.5.4 or later to address 10 fixable vulnerabilities
CVE-2025-64248
Multiple Plugins by eMarket Design <= Various Versions - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Request a Quote Plugin <= 2.5.2 is vulnerable to Remote Code Execution (RCE)
CVE-2024-6231
WordPress Request a Quote Plugin < 2.3.11 is vulnerable to Cross Site Request Forgery (CSRF)
Request a Quote <= 2.3.10 - Cross-Site Request Forgery
CVE-2022-2240
CVE-2022-2239
WordPress Request a Quote plugin <= 2.3.7 - CSV Injection vulnerability
WordPress Request a Quote plugin <= 2.3.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2021-24420
CVE-2021-24489