• PATCH AVAILABLE

CVE-2026-84238: pre-auth broken access control in YITH YITH Request a Quote for WooCommerce Premium

An unauthenticated remote attacker can bypass access controls in the YITH Request a Quote for WooCommerce Premium plugin, allowing unauthorized actions against sites using the vulnerable plugin. This is tracked as CVE-2026-84238 and scores 9.8 CVSSv3.1. The flaw affects the 4.x branch before version 4.46.0; an attacker only needs network access to a site running the vulnerable plugin and does not require a valid account or user interaction to exploit the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00483
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remotely reachable, unauthenticated access-control bypass with a 9.8 CVSS score; prioritize updating because the vendor released a fixed 4.46.0 build.

What is CVE-2026-84238?

An unauthenticated remote attacker can bypass access controls in the YITH Request a Quote for WooCommerce Premium plugin, allowing unauthorized actions against sites using the vulnerable plugin. This is tracked as CVE-2026-84238 and scores 9.8 CVSSv3.1. The flaw affects the 4.x branch before version 4.46.0; an attacker only needs network access to a site running the vulnerable plugin and does not require a valid account or user interaction to exploit the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of YITH YITH Request a Quote for WooCommerce Premium are affected?

BRANCHAFFECTEDFIXED
4.xbefore 4.46.04.46.0

Is CVE-2026-84238 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-84238

  1. Upgrade YITH Request a Quote for WooCommerce Premium on affected sites to 4.46.0.
  2. If immediate upgrade is not possible, restrict plugin endpoints with network controls or web application firewall rules to limit external access.
  3. Monitor web and application logs for unexpected requests and access patterns against the plugin’s endpoints.
  4. Follow vendor guidance and verify updates on a test site before rolling out to production.

Frequently asked questions

Is CVE-2026-84238 being actively exploited?

There are no public reports of exploitation of CVE-2026-84238 as of 2026-09-29.

Which YITH Request a Quote for WooCommerce Premium versions are affected by CVE-2026-84238?

Versions in the 4.x branch before 4.46.0 of YITH Request a Quote for WooCommerce Premium are affected.

Is there a patch for CVE-2026-84238?

Yes. The issue is fixed in YITH Request a Quote for WooCommerce Premium version 4.46.0.

Does CVE-2026-84238 require authentication?

No. CVE-2026-84238 is an unauthenticated broken access control vulnerability and does not require a valid account.

References