← Terug naar overzicht

CVE-2026-84238 describes an unauthenticated Broken Access Control vulnerability affecting the YITH Request a Quote for WooCommerce Premium plugin in versions prior to 4.46.0. The flaw allows unauthenticated users to bypass access controls, potentially accessing or manipulating restricted functionality within the WooCommerce environment. This type of vulnerability can expose sensitive e-commerce data and business logic to unauthorized actors. The issue has been documented by both the NVD (NIST) and Patchstack. The fix is available in version 4.46.0 and later. WordPress site administrators running the affected plugin versions should update immediately. Broken Access Control vulnerabilities are consistently ranked among the most critical web application security risks. No additional technical details such as CVSS score or exploit code are provided in the article.

Affected products

  • YITH Request a Quote for WooCommerce Premium < 4.46.0

Related CVE's

  • CVE-2026-84238

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies