First published: Thu Mar 20 2025(Updated: )
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
NP Quote Request for WooCommerce | <1.9.180 | |
NP Quote Request for WooCommerce | <=1.9.179 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13558 is classified as a critical vulnerability due to its potential for unauthenticated access to sensitive content.
To remediate CVE-2024-13558, update the NP Quote Request for WooCommerce plugin to the latest version beyond 1.9.179.
People using the NP Quote Request for WooCommerce plugin in versions up to and including 1.9.179 are vulnerable to CVE-2024-13558.
CVE-2024-13558 is an Insecure Direct Object Reference vulnerability that arises from insufficient validation on user-controlled keys.
No, CVE-2024-13558 can be exploited by unauthenticated attackers, which makes it particularly dangerous.