CVE-2026-84238
9.8YITH · Request a Quote for WooCommerce Premium
YITH Request a Quote for WooCommerce Premium versions prior to 4.46.0 contain an unauthenticated broken access control vulnerability, allowing unauthorized access to restricted plugin functions.
Executive summary
This critical vulnerability allows unauthenticated attackers to bypass authorization controls in the YITH Request a Quote for WooCommerce Premium plugin, posing a severe risk of complete system compromise.
Vulnerability
The plugin suffers from a missing authorization flaw (CWE-862) that allows unauthenticated remote attackers to perform unauthorized actions. Because the vulnerability requires no interaction or credentials, it is highly accessible for exploitation.
Business impact
The flaw carries a CVSS score of 9.8, indicating a critical severity level that could lead to unauthorized data access, modification of quote requests, or potential takeover of the WooCommerce store functionality. This exposure threatens the integrity of customer data and business operations, potentially leading to significant financial loss and reputational damage.
Remediation
Immediate Action: Update the YITH Request a Quote for WooCommerce Premium plugin to version 4.46.0 or later immediately.
Proactive Monitoring: Review web server access logs for anomalous requests directed at plugin-specific endpoints, particularly those originating from unknown or suspicious IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts targeting WordPress plugin endpoints until the update is successfully applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The critical nature of this vulnerability, combined with the lack of authentication requirements, necessitates immediate action. Administrators must prioritize updating the YITH Request a Quote for WooCommerce Premium plugin to version 4.46.0 or higher to eliminate this attack vector and secure the WooCommerce environment against unauthorized access.