CVE-2024-13558

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Mar 27, 2025
CWE ID 639

Summary

CVE-2024-13558 is a vulnerability affecting the NP Quote Request plugin for WooCommerce on WordPress. Impacting versions up to 1.9.179, this issue stems from a lack of validation on user-controlled keys. As a result, unauthenticated attackers can exploit this vulnerability to gain unauthorized access to quote request content. The missing validation allows attackers to bypass intended access controls and potentially obtain sensitive information. This insecure direct object reference (IDOR) vulnerability poses a significant risk to WordPress sites using the NP Quote Request plugin and highlights the importance of regular security updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share