Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key. | |
| Title | NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:50:31.334Z
Reserved: 2026-09-18T08:48:04.420Z
Link: CVE-2026-93528
Updated: 2026-09-23T10:32:09.465Z
Status : Received
Published: 2026-09-23T06:17:06.273
Modified: 2026-09-23T11:17:18.400
Link: CVE-2026-93528
No data.
OpenCVE Enrichment
Updated: 2026-09-23T15:15:05Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor