Unauthorized Access to Quote Data in Woocommerce Request A Quote Plugin
CVE-2024-9430
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 October 2024
What is CVE-2024-9430?
The Get Quote For Woocommerce β Request A Quote For Woocommerce plugin for WordPress is susceptible to unauthorized access of Quote data due to the lack of a capability check on the ct_tepfw_wp_loaded function. This vulnerability enables unauthenticated attackers to gain access to and download sensitive Quote PDF and CSV documents from the affected versions, specifically all releases up to and including 1.0.0. Website administrators should take immediate action to secure their installations and prevent potential data leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Get Quote For Woocommerce β Request A Quote For Woocommerce * <= 1.0.0
References
CVSS V3.1
Timeline
Vulnerability published