Security update needed in version 2.3.9
-
Patchstack currently lists ELEX WooCommerce Request a Quote versions 2.3.9 and earlier as vulnerable to a Broken Access Control issue identified as CVE-2025-31406. Patchstack indicates that an official patch is not currently available:
The latest version available through WordPress is still version 2.3.9. We have also contacted the ELEX support team directly but have not received a response.
Could you please confirm whether a security update is being developed? If so, is there an estimated release date or patched version number?
If this issue has already been resolved, please provide the applicable version number and update the vulnerability record with Patchstack so that security-monitoring services no longer flag the plugin.
Thank you.
The page I need help with: [log in to see the link]
You must be logged in to reply to this topic.