CVE-2024-13558

HIGH

Neahplugins NP Quote Request For Woocommerce < 1.9.180 - IDOR

Title source: rule
STIX 2.1

Description

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests.

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
gplsaver/NP Quote Request for WooCommerce < 1.9.179
neahplugins/np_quote_request_for_woocommerce < 1.9.180
Published Mar 20, 2025
Tracked Since Feb 18, 2026