CVE-2026-95602

6.5

YITH · YITH WooCommerce Request A Quote

An authorization bypass vulnerability in YITH WooCommerce Request A Quote allows unauthenticated attackers to manipulate access controls via user-controlled keys.

Executive summary

The YITH WooCommerce Request A Quote plugin is vulnerable to an authorization bypass flaw that permits unauthorized modification of access control settings by unauthenticated users.

Vulnerability

This vulnerability is an Authorization Bypass Through User-Controlled Key (CWE-639) that occurs because the plugin fails to properly validate user-supplied keys during access control checks. The attack vector is network-based and does not require authentication, allowing any remote user to potentially exploit the misconfiguration.

Business impact

The ability for unauthenticated users to bypass authorization mechanisms poses a significant risk to the integrity of the WooCommerce environment. While the CVSS score of 6.5 suggests a medium severity, the potential for unauthorized access to sensitive business logic or quote management functions could lead to data manipulation or operational disruption. Organizations should prioritize this update to prevent unauthorized entities from gaining elevated control over plugin features.

Remediation

Immediate Action: Update the YITH WooCommerce Request A Quote plugin to version 4.46.1 or later immediately to resolve the identified authorization flaw.

Proactive Monitoring: Review web server and application access logs for unusual requests directed at plugin-specific endpoints, particularly those associated with quote management or administrative configuration.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns targeting WooCommerce plugin parameters, which may provide temporary mitigation until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the ease of exploitation for this vulnerability, administrators must treat this update with high priority. Ensure that all instances of the YITH WooCommerce Request A Quote plugin are updated to version 4.46.1 or higher to eliminate the risk of unauthorized access. Failure to remediate this vulnerability leaves the store susceptible to unauthorized modifications of quote-related access controls.

More YITH CVEs

History

  1. Analyst report written