CVE-2026-93528EPSS p11.2%
CVE-2026-93528CVE-2026-93528
Description
The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
Scoring
| CVSS | 3.7 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.22% probability of exploitation · percentile 11.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-23 |