ZeroHour

CVE-2026-84238

moderate

Unauthenticated Broken Access Control in YITH Request a Quote Premium

CVSS 3.1
9.8 critical
EPSS
<1%p19
Published
()
Modified
AI analysis

YITH Request a Quote for WooCommerce Premium, in versions before 4.46.0, contains an unauthenticated broken access control flaw classified as CWE-862 (Missing Authorization), meaning functionality that should verify a user's permissions performs no authorization check at all. Because no credentials are required, any remote attacker can trigger the affected functionality directly over the network with no user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). The critical 9.8 rating, with high impact to confidentiality, integrity, and availability, indicates an attacker can access protected functionality and data as if authorized, exposing or manipulating sensitive quote and store information. All deployments of the Premium edition prior to 4.46.0 are affected; the free edition is not named in the advisory. There is currently no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at just 0.3% (19th percentile), so no in-the-wild exploitation is documented.

What to do: Upgrade YITH Request a Quote for WooCommerce Premium to version 4.46.0 or later, and confirm the installed version on the WordPress plugins screen. Since the flaw is exploitable without credentials and no public PoC exists, a WAF rule restricting unauthenticated access to the plugin's endpoints is a reasonable interim measure while patching. No other mitigations are documented in the available advisory data.

Affected
YITH Request a Quote for WooCommerce Premium (WordPress/WooCommerce plugin)< 4.46.0
Estimated exposure
moderatelikely roughly 1,000-10,000 premium sites (free edition lists ~20,000+ active installs; premium is a paid subset) — Estimated from the free edition's roughly 20,000+ WordPress.org active installs, with paid premium deployments typically forming a smaller subset of that user base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

Ecosystems
WordPress, E-commerce
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.