The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
CVE-2026-93528
NONE
Updated Sep 23, 2026
WordPress
CVE Details
CVE ID
CVE-2026-93528
Published Date
Sep 23, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory