CRITICAL 9.8 CVE-2026-84238 Published 3 Sept 2026

WooCommerce YITH Quote Plugin Access Control Flaw

Worried this affects one of your servers?

Unauthenticated users can exploit a broken access control vulnerability in the YITH Request a Quote for WooCommerce Premium plugin, versions prior to 4.46.0.

YITH Request a Quote plugin for WooCommerce allows customers to request a quote for products, but an unauthenticated user can bypass this functionality and directly access the quote request page.

Reference: CVE-2026-84238 on NVD

← Back to Security News