سایبرنامه
low

CVE-2026-93528

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

امتیاز CVSS

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

تحلیلِ بردارِ CVSS

CWE
CWE-200
تاریخ انتشار
۱ مهر ۱۴۰۵

منابع