Impact
The NP Quote Request for WooCommerce WordPress plugin performs no ownership verification when rendering an order’s details, allowing an unauthenticated attacker to view another customer’s order by supplying that order’s key. This flaw results in the disclosure of sensitive order information; it is an information disclosure (CWE‑200) that impacts confidentiality but not integrity or availability.
Affected Systems
WordPress sites that have installed NP Quote Request for WooCommerce version 2.4.15 or earlier are affected. Sites running version 2.4.16 or later are not vulnerable, as the issue has been fixed in that release. The vendor is listed as Unknown:NP Quote Request for WooCommerce, so any organization using the plugin should verify the installed version and upgrade accordingly.
Risk and Exploitability
The CVSS score of 3.7 places this vulnerability in the low‑to‑moderate severity range. The EPSS score is below 1 %, indicating a very low expected exploitation probability. Since it is not included in the CISA Known Exploited Vulnerabilities catalog, no publicly known exploits have been observed. The likely attack vector is Web‑based: by accessing or guessing the order key, an unauthorized user can trigger the disclosure. The vulnerability does not require elevated privileges, but guessable or brute‑forceable order keys could enable exploitation.
OpenCVE Enrichment