VYPR
Unrated severityNVD Advisory· Published Sep 23, 2026

CVE-2026-93528

CVE-2026-93528

Description

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.