Loading market data...
← Back to CVE feed

CVE-2026-93528

LOW CVSS 3.7 View on NVD ↗

Description

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 23, 2026 06:17 UTC Modified: Sep 23, 2026 18:12 UTC