YITH Request a Quote for WooCommerce Premium Unauthenticated Broken Access Control

Release Date: 3rd September 2026 (Added 8th September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and e-commerce teams that operate a WooCommerce-based WordPress store using the YITH Request a Quote for WooCommerce Premium extension. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-84238 is a critical, unauthenticated broken access control vulnerability in YITH Request a Quote for WooCommerce Premium, a paid extension by YITH (Your Inspiration Themes) - an established WooCommerce extension vendor whose free companion plugin alone has 10,000+ active installations on WordPress.org that lets store owners hide prices and “Add to cart” buttons and instead let customers request custom quotes.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-84238
  2. https://yithemes.com/themes/plugins/yith-woocommerce-request-a-quote/