The Request a Quote plugin for WordPress is vulnerable to a security flaw in versions up to 2.3.10. It does not have the necessary safety features to prevent unauthenticated attackers from changing the plugin’s settings. This can be done if the attacker can persuade a site administrator to click on a malicious link.