CVE-2026-84238: WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress YITH Request a Quote for WooCommerce Premiumto a version that resolves this vulnerability.Fixed in 4.46.0
Event History
Frequently Asked Questions
Does exploitation require an authenticated WordPress or WooCommerce account?
No. The vulnerability is described as unauthenticated, so an attacker does not need a WordPress or WooCommerce account to exploit the affected plugin.
Which installations are affected?
Installations using YITH Request a Quote for WooCommerce Premium versions earlier than 4.46.0 are affected. The provided data does not state whether any particular plugin settings or non-default configuration are required.
What is the potential impact of successful exploitation?
The vulnerability is rated critical with a CVSS score of 9.8 and network-based, low-complexity exploitation. It is assessed as having high impact on confidentiality, integrity, and availability.