Description
The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
Published: 2026-09-23
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Order Data Disclosure
Action: Update
AI Analysis

Impact

The NP Quote Request for WooCommerce WordPress plugin performs no ownership verification when rendering an order’s details, allowing an unauthenticated attacker to view another customer’s order by supplying that order’s key. This flaw results in the disclosure of sensitive order information; it is an information disclosure (CWE‑200) that impacts confidentiality but not integrity or availability.

Affected Systems

WordPress sites that have installed NP Quote Request for WooCommerce version 2.4.15 or earlier are affected. Sites running version 2.4.16 or later are not vulnerable, as the issue has been fixed in that release. The vendor is listed as Unknown:NP Quote Request for WooCommerce, so any organization using the plugin should verify the installed version and upgrade accordingly.

Risk and Exploitability

The CVSS score of 3.7 places this vulnerability in the low‑to‑moderate severity range. The EPSS score is below 1 %, indicating a very low expected exploitation probability. Since it is not included in the CISA Known Exploited Vulnerabilities catalog, no publicly known exploits have been observed. The likely attack vector is Web‑based: by accessing or guessing the order key, an unauthorized user can trigger the disclosure. The vulnerability does not require elevated privileges, but guessable or brute‑forceable order keys could enable exploitation.

Generated by OpenCVE AI on September 23, 2026 at 15:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NP Quote Request for WooCommerce to version 2.4.16 or newer.
  • If an immediate update is not possible, block or restrict access to the quote request page so that only authenticated users can view order details.
  • Continuously monitor web access logs for suspicious requests to the quote request endpoints to detect potential misuse.

Generated by OpenCVE AI on September 23, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
Title NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:50:31.334Z

Reserved: 2026-09-18T08:48:04.420Z

Link: CVE-2026-93528

cve-icon Vulnrichment

Updated: 2026-09-23T10:32:09.465Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:06.273

Modified: 2026-09-23T11:17:18.400

Link: CVE-2026-93528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:15:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor