---
id: CVE-2026-93528
title: >-
  The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not
  verify order ownership before rendering an order's details, allowing
  unauthenticated attackers to view another customer's order using the order's
  key.
summary: >-
  The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not
  verify order ownership before rendering an order's details, allowing
  unauthenticated attackers to view another customer's order using the order's
  key.
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: NP Quote Request for WooCommerce
affected:
  - np_quote_request_for_woocommerce >= 2.0 < 2.4.16
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:12:32.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93528'
references:
  - url: 'https://wpscan.com/vulnerability/f691b9cc-7d17-4308-9646-db842d99f63f/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00199
epssPercentile: 0.10047
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/muradislamzada/CVE-2026-93528'
  checkedAt: '2026-09-23T18:30:08.235Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T10:35:55.272788Z'
ingestedAt: '2026-09-23T06:17:57.902Z'
---

## Overview

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
