CVE-2026-84238: Patch for YITH Request a Quote for WooCommerce Premium
This text was generated using artificial intelligence (AI).On September 3, 2026, CVE-2026-84238 for YITH Request a Quote for WooCommerce Premium Published. Affected are versions prior to 4.46.0. Patchstack assigns a CVSS score of 9.8 as well as the classification CWE-862: Missing Authorization from.
For affected installations, an update to Version 4.46.0 or later ...is recommended. Organizations should check the patch status and vulnerability status of the plugin instances they are using.
CVE-2026-84238 describes an unauthenticated broken access control vulnerability in the YITH Request a Quote for WooCommerce premium plugin. The vulnerability is classified as CWE-862, "Missing Authorization.".
Patchstack documents the CVSS string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This entry applies exclusively to YITH Request a Quote for WooCommerce Premium versions prior to 4.46.0.
Measures for Affected Installations
The patch status should be checked against the affected version range. For installations prior to version 4.46.0, an update to version 4.46.0 or higher is recommended.
Recommended steps:
Check the installation and version of YITH Request a Quote for WooCommerce Premium.
Prioritize and mitigate affected systems.
Update to version 4.46.0 or later.
Enable Patchstack Virtual Patch as a temporary solution if the plugin update cannot be performed immediately.
Establish continuous vulnerability and vendor risk monitoring.
WooCommerce-based e-commerce platforms are widely used in the DACH markets. Operators for whom an exploit of CVE-2026-84238 has resulted in the processing or leakage of personal data are subject to the reporting obligation under Article 33 of the GDPR (72-hour deadline to notify the competent supervisory authority). Operators subject to NIS 2 in Germany and Austria, as well as organizations covered by Switzerland’s revised Information Security Act (ISG/BACS), should review their plugin inventory and the respective patch status.
Visibility of Externally Accessible E-commerce Platforms
YITH Request a Quote for WooCommerce Premium is deployed on a customer's website domain. WooCommerce instances can be identified externally based on technical characteristics such as HTTP headers, JavaScript assets, and plugin paths.
LocateRisk identifies externally accessible assets and software in use. This allows publicly accessible WooCommerce instances to be included in the scan and correlated with plugin fingerprints. The visibility of a plugin does not replace a check of the installed version: Whether an instance is affected by CVE-2026-84238 must be determined based on the version.
Continuous vulnerability and vendor risk monitoring helps ensure that the technologies in use and the associated responsibilities are consistently factored into operational processes.
Am I affected?
This affects YITH Request a Quote for WooCommerce Premium in the versions listed above; the vulnerability was fixed in version 4.46.0. If you want to know whether YITH Request a Quote for WooCommerce Premium is even visible on your own externally accessible infrastructure, you can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-84238 refers to an unauthenticated broken access control vulnerability (CWE-862: Missing Authorization) in the WordPress plugin YITH Request a Quote for WooCommerce Premium. The CVSS score is 9.8 (critical), indicating that the vulnerability can be exploited over the network without requiring authentication.
All versions of the plugin prior to 4.46.0 are affected. Updating to version 4.46.0 or higher resolves the vulnerability. According to Patchstack, a virtual patch is available as a temporary measure.
As of the date of publication on September 3, 2026, according to Patchstack, there are no known active exploits for CVE-2026-84238.
As of September 3, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-84238
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.