rootpwn

low · CVSS v3 3.7 · EPSS 0.00199

CVE-2026-93528

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an …

Description

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
EPSS
0.00199

← All CVEs