Unauthorized Access to Quote Data in Woocommerce Request A Quote Plugin
CVE-2024-9430
5.3MEDIUM
What is CVE-2024-9430?
The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is susceptible to unauthorized access of Quote data due to the lack of a capability check on the ct_tepfw_wp_loaded function. This vulnerability enables unauthenticated attackers to gain access to and download sensitive Quote PDF and CSV documents from the affected versions, specifically all releases up to and including 1.0.0. Website administrators should take immediate action to secure their installations and prevent potential data leakage.