CVE-2026-95602: WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YITH WooCommerce Request A Quoteto a version that resolves this vulnerability.Fixed in 4.46.1
Event History
Frequently Asked Questions
Which installations are affected?
YITH WooCommerce Request A Quote versions before 4.46.1 are affected. The available data does not identify a lower bound for affected versions.
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates that exploitation is network-accessible, requires no privileges, and requires no user interaction.
What impact can successful exploitation have?
The supplied CVSS vector indicates low integrity and availability impact, with no confidentiality impact. The issue is described as an authorization bypass through a user-controlled key and incorrectly configured access-control levels.
What version addresses the issue?
Version 4.46.1 is the first version identified as not affected; versions before it are affected.