CVE-2026-93528

NONE
Updated Sep 23, 2026
WordPress
Parameter Value
Affected Versions before 2.4.16
Vendor WordPress
Public PoC No

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.