Junglewise Threat Intelligence

CVE-2026-84238: YITH Request a Quote for WooCommerce Premium broken access control

CVE-2026-84238 · Severity: critical · CVSS 9.8 · Published 2026-09-03

Vendors: YITH.

Executive brief

YITH Request a Quote for WooCommerce Premium is a WordPress plugin that allows customers to request quotes for products. An unauthenticated broken access control vulnerability allows attackers to access pages and perform actions they should not be permitted to, including viewing other customers' quote data and potentially manipulating requests without proper authorization.

Technical details

The vulnerability is a broken access control flaw in YITH Request a Quote for WooCommerce Premium versions prior to 4.46.0. The plugin fails to properly validate user permissions before granting access to sensitive quote request pages and functionality, allowing unauthenticated attackers to bypass access checks via network requests. An attacker can view or manipulate quote requests belonging to other users, expose customer data, and potentially tamper with business operations. The vulnerability is patched in version 4.46.0 and later.

Affected products

  • YITH Request a Quote for WooCommerce Premium < 4.46.0

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: patched in version 4.46.0

References