Impact
This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the YITH WooCommerce Request A Quote plugin, classified as CWE-639. It allows an attacker to bypass access controls by manipulating user‐controlled parameters, such as request identifiers or URLs, to view or modify quote requests that belong to other customers. The potential consequence is that personal or commercial information associated with these requests could be exposed or altered, compromising confidentiality and the integrity of the quotation system.
Affected Systems
The affected product is YITH WooCommerce Request A Quote for WordPress, specifically all releases older than version 4.46.1. No additional version ranges are specified, so any installation using a pre‑4.46.1 build is considered vulnerable. The vendor responsible for the flaw is YITH.
Risk and Exploitability
The CVSS score of 6.5 places the issue in the medium severity range, indicating that exploitation could have a significant impact on affected sites. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no current evidence of widespread exploited attacks. Based on the description, the likely attack vector is remote network access via the web interface, where an attacker crafts or modifies a request parameter to resolve the quote identifier of another user.
OpenCVE Enrichment