CVE-2024-13558
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-13558 is a vulnerability affecting the NP Quote Request plugin for WooCommerce on WordPress. Impacting versions up to 1.9.179, this issue stems from a lack of validation on user-controlled keys. As a result, unauthenticated attackers can exploit this vulnerability to gain unauthorized access to quote request content. The missing validation allows attackers to bypass intended access controls and potentially obtain sensitive information. This insecure direct object reference (IDOR) vulnerability poses a significant risk to WordPress sites using the NP Quote Request plugin and highlights the importance of regular security updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.