CVE-2024-13558
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests.
Affected (1)
Products: Neahplugins: Np Quote Request For Woocommerce
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.9.180 |
References (3)
Source: security@wordfence.com
Product
Source: security@wordfence.com
Third Party Advisory
Timeline
No history available yet.