{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-93528", "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "state": "PUBLISHED", "assignerShortName": "WPScan", "dateReserved": "2026-09-18T08:48:04.420Z", "datePublished": "2026-09-23T06:00:23.938Z", "dateUpdated": "2026-09-23T10:50:31.334Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "shortName": "WPScan", "dateUpdated": "2026-09-23T06:00:23.938Z" }, "title": "NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page", "problemTypes": [ { "descriptions": [ { "description": "CWE-200 Information Exposure", "lang": "en", "type": "CWE" } ] } ], "affected": [ { "vendor": "Unknown", "product": "NP Quote Request for WooCommerce", "versions": [ { "status": "affected", "versionType": "semver", "version": "2.0", "lessThan": "2.4.16" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key." } ], "references": [ { "url": "https://wpscan.com/vulnerability/f691b9cc-7d17-4308-9646-db842d99f63f/", "tags": [ "exploit", "vdb-entry", "technical-description" ] } ], "credits": [ { "lang": "en", "value": "Murad Islamzada", "type": "finder" }, { "lang": "en", "value": "WPScan", "type": "coordinator" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "WPScan CVE Generator" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-200", "lang": "en", "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor" } ] } ], "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-23T10:35:55.272788Z", "id": "CVE-2026-93528", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-23T10:50:31.334Z" } } ] } }