CVE-2026-93528: Unknown Np Quote Request For Woocommerce

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

Affected products

  • Unknown Np Quote Request For Woocommerce: from 2.0, before 2.4.16 (fixed in 2.4.16)

Published 2026-09-23. Last modified 2026-09-23.