Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-84238: YITH Quote Plugin for WooCommerce (versions before 4.46) lets anyone change settings
CVE-2026-84238 · published today
Summary
The premium YITH "Request a Quote" add‑on for WooCommerce can be accessed without logging in, allowing anyone on the internet to view or modify its configuration. This could let attackers alter how quotes are handled or expose sensitive data. Update the plugin to version 4.46 or later, or remove it until you can apply the fix.
What to do
- Update yith yith request a quote for woocommerce premium to version 4.46.0.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| yith | yith request a quote for woocommerce premium |
< 4.46.0 Fix: upgrade to 4.46.0
|
Original advisory text
WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
References
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-862Missing Authorization
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta