External risk intelligence

YITH Request a Quote for WooCommerce Premium Unauthenticated Broken Access Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84238

The vulnerability affects a WordPress WooCommerce plugin designed to manage customer interactions. As a plugin for an e-commerce platform, it is commonly deployed on public-facing websites where the request-a-quote functionality is exposed to the internet to facilitate user engagement.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in a popular e-commerce plugin for WordPress, potentially allowing unauthorized access to sensitive information and system functions. This vulnerability impacts how user requests are managed, and its widespread use in online stores means a broad range of businesses could be at risk if not properly addressed. The primary concern is to confirm if your organization utilizes this specific plugin and assess its exposure.

  • Unauthenticated access control flaw found.
  • Impacts online stores using a quote request plugin.
  • Verify usage and confirm exposure promptly.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by interacting with the Request a Quote feature of the YITH WooCommerce plugin. Because the vulnerability is in broken access control, an attacker could bypass intended restrictions to access or modify quote data, potentially leading to significant compromise.

  • No authentication required.
  • Triggered via website's quote feature.
  • Compromise of sensitive quote data.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could exploit a broken access control flaw in the YITH Request a Quote for WooCommerce Premium plugin. This could allow unauthorized access to sensitive information, modification of system data, or disruption of service, particularly when the plugin's request-a-quote functionality is exposed online.

  • Plugin data and service integrity.
  • Via unauthenticated network requests.
  • Compromised site functionality and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a WooCommerce plugin likely impacts e-commerce platforms managed by application owners, with potential involvement from infrastructure or platform teams depending on deployment. The immediate first step is to identify all instances of the affected plugin, confirm their exposure and business criticality, and then assign ownership for remediation planning.

  • Application owners should address the issue.
  • Verify plugin exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the YITH Request a Quote for WooCommerce Premium plugin?

This software is a WordPress extension designed for online stores to allow customers to negotiate prices or inquire about bulk orders. By enabling a formal quoting workflow, it handles sensitive customer interactions and pricing data within the WooCommerce e-commerce ecosystem.

What does broken access control mean for CVE-2026-84238?

This vulnerability, classified as CWE-862, occurs when software fails to properly verify if a user has permission to perform a specific action. In this case, the plugin does not correctly check the identity of the user, allowing someone without authorization to access or manipulate data that should be protected.

How is this vulnerability triggered by an attacker?

An attacker initiates this by sending unauthorized network requests directly to the plugin's quote management features. The bug is triggered because the system accepts these requests without requiring any login credentials. It is not triggered by standard customer interactions that fall within the normal, intended use of the quoting system.

Do I need to worry if my site is internal?

According to Halo Surface Signal, this plugin is primarily designed for public-facing e-commerce websites to facilitate customer engagement. While internal instances may be less accessible to external attackers, any installation that is reachable over a network should be evaluated for risk based on how your organization exposes its web services.

When should I take action on CVE-2026-84238?

You should prioritize identifying all instances of this plugin in your environment immediately. Confirm which sites are running versions older than 4.46.0 and determine the business criticality of those specific installations to plan your update strategy accordingly.

References