CVE-2026-84238
moderateUnauthenticated Broken Access Control in YITH Request a Quote Premium
YITH Request a Quote for WooCommerce Premium, in versions before 4.46.0, contains an unauthenticated broken access control flaw classified as CWE-862 (Missing Authorization), meaning functionality that should verify a user's permissions performs no authorization check at all. Because no credentials are required, any remote attacker can trigger the affected functionality directly over the network with no user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). The critical 9.8 rating, with high impact to confidentiality, integrity, and availability, indicates an attacker can access protected functionality and data as if authorized, exposing or manipulating sensitive quote and store information. All deployments of the Premium edition prior to 4.46.0 are affected; the free edition is not named in the advisory. There is currently no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at just 0.3% (19th percentile), so no in-the-wild exploitation is documented.
What to do: Upgrade YITH Request a Quote for WooCommerce Premium to version 4.46.0 or later, and confirm the installed version on the WordPress plugins screen. Since the flaw is exploitable without credentials and no public PoC exists, a WAF rule restricting unauthenticated access to the plugin's endpoints is a reasonable interim measure while patching. No other mitigations are documented in the available advisory data.
| YITH Request a Quote for WooCommerce Premium (WordPress/WooCommerce plugin) | < 4.46.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.