Unrated severityNVD Advisory· Published Sep 23, 2026
CVE-2026-93528
CVE-2026-93528
Description
The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.