CRITICAL
9.8 CVE-2026-84238 Published 3 Sept 2026
WooCommerce YITH Quote Plugin Access Control Flaw
Worried this affects one of your servers?
Unauthenticated users can exploit a broken access control vulnerability in the YITH Request a Quote for WooCommerce Premium plugin, versions prior to 4.46.0.
YITH Request a Quote plugin for WooCommerce allows customers to request a quote for products, but an unauthenticated user can bypass this functionality and directly access the quote request page.
Reference: CVE-2026-84238 on NVD
← Back to Security News