Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-84238: YITH Quote Plugin for WooCommerce (versions before 4.46) lets anyone change settings

CVE-2026-84238 · published today
Summary

The premium YITH "Request a Quote" add‑on for WooCommerce can be accessed without logging in, allowing anyone on the internet to view or modify its configuration. This could let attackers alter how quotes are handled or expose sensitive data. Update the plugin to version 4.46 or later, or remove it until you can apply the fix.

What to do
  • Update yith yith request a quote for woocommerce premium to version 4.46.0.
Affected software
VendorProductAffected versions
yith yith request a quote for woocommerce premium < 4.46.0
Fix: upgrade to 4.46.0
Original advisory text
WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-862Missing Authorization
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2026-84238 · MITRE
Monitor software like this
Free during beta