Description
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.
Published: 2026-09-23
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the YITH WooCommerce Request A Quote plugin, classified as CWE-639. It allows an attacker to bypass access controls by manipulating user‐controlled parameters, such as request identifiers or URLs, to view or modify quote requests that belong to other customers. The potential consequence is that personal or commercial information associated with these requests could be exposed or altered, compromising confidentiality and the integrity of the quotation system.

Affected Systems

The affected product is YITH WooCommerce Request A Quote for WordPress, specifically all releases older than version 4.46.1. No additional version ranges are specified, so any installation using a pre‑4.46.1 build is considered vulnerable. The vendor responsible for the flaw is YITH.

Risk and Exploitability

The CVSS score of 6.5 places the issue in the medium severity range, indicating that exploitation could have a significant impact on affected sites. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no current evidence of widespread exploited attacks. Based on the description, the likely attack vector is remote network access via the web interface, where an attacker crafts or modifies a request parameter to resolve the quote identifier of another user.

Generated by OpenCVE AI on September 23, 2026 at 20:01 UTC.

Remediation

Vendor Solution

Update the WordPress YITH WooCommerce Request A Quote Plugin to the latest available version (at least 4.46.1).


OpenCVE Recommended Actions

  • Upgrade the YITH WooCommerce Request A Quote plugin to version 4.46.1 or later.
  • If the plugin is not required, disable or remove it from the WordPress installation to eliminate the attack surface.
  • Implement strict access checks to confirm the requesting user is the owner of the quote request before allowing read or write operations.

Generated by OpenCVE AI on September 23, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in YITH WooCommerce Request A Quote < 4.46.1 versions. Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in YITH WooCommerce Request A Quote < 4.46.1 versions.
Title WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T18:46:50.982Z

Reserved: 2026-09-22T09:18:20.379Z

Link: CVE-2026-95602

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:53.350

Modified: 2026-09-23T19:39:08.847

Link: CVE-2026-95602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:15:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key