Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6800 | The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests. |
Thu, 27 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Neahplugins
Neahplugins np Quote Request For Woocommerce |
|
| CPEs | cpe:2.3:a:neahplugins:np_quote_request_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Neahplugins
Neahplugins np Quote Request For Woocommerce |
Thu, 20 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests. | |
| Title | NP Quote Request for WooCommerce <= 1.9.179 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:54:51.836Z
Reserved: 2025-01-20T22:32:09.171Z
Link: CVE-2024-13558
Updated: 2025-03-20T13:23:09.241Z
Status : Analyzed
Published: 2025-03-20T12:15:13.193
Modified: 2025-03-27T15:27:56.993
Link: CVE-2024-13558
No data.
OpenCVE Enrichment
No data.
EUVD