DIRAS TAKE
Urgent: this is a remotely reachable, unauthenticated access-control bypass with a 9.8 CVSS score; prioritize updating because the vendor released a fixed 4.46.0 build.
What is CVE-2026-84238?
An unauthenticated remote attacker can bypass access controls in the YITH Request a Quote for WooCommerce Premium plugin, allowing unauthorized actions against sites using the vulnerable plugin. This is tracked as CVE-2026-84238 and scores 9.8 CVSSv3.1. The flaw affects the 4.x branch before version 4.46.0; an attacker only needs network access to a site running the vulnerable plugin and does not require a valid account or user interaction to exploit the issue.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of YITH YITH Request a Quote for WooCommerce Premium are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 4.x | before 4.46.0 | 4.46.0 |
Is CVE-2026-84238 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84238
- Upgrade YITH Request a Quote for WooCommerce Premium on affected sites to 4.46.0.
- If immediate upgrade is not possible, restrict plugin endpoints with network controls or web application firewall rules to limit external access.
- Monitor web and application logs for unexpected requests and access patterns against the plugin’s endpoints.
- Follow vendor guidance and verify updates on a test site before rolling out to production.
Frequently asked questions
Is CVE-2026-84238 being actively exploited?
There are no public reports of exploitation of CVE-2026-84238 as of 2026-09-29.
Which YITH Request a Quote for WooCommerce Premium versions are affected by CVE-2026-84238?
Versions in the 4.x branch before 4.46.0 of YITH Request a Quote for WooCommerce Premium are affected.
Is there a patch for CVE-2026-84238?
Yes. The issue is fixed in YITH Request a Quote for WooCommerce Premium version 4.46.0.
Does CVE-2026-84238 require authentication?
No. CVE-2026-84238 is an unauthenticated broken access control vulnerability and does not require a valid account.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84238
- cve.org/CVERecord?id=CVE-2026-84238
- patchstack.com/database/wordpress/plugin/yith-woocommerce-request-a-quote-premium/vulnerability/wordpress-yith-request-a-quote-for-woocommerce-premium-plugin-4-46-0-broken-access-control-vulnerability?_s_id=cve
- All YITH CVEs on CVE Radar
- CVEs published in September 2026