CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce <= 6.1.5 - Unauthenticated Insecure Direct Object Reference to Arbitrary Order Status Modification via 'orderId' Parameter
- ID
- WPSEC-2026-0578
- Plugin
- CatalogX Product Catalog, Product Enquiry & Quotes for WooCommerce (woocommerce-catalog-enquiry)
- Affected
- from 6.0.0 before 6.1.6
- Remediation
- Update to 6.1.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The CatalogX - Catalog Mode, Enquiry & Quotes for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 6.0.0 up to, and including, 6.1.5 due to missing validation on the user-controlled 'orderId' parameter in the quote rejection handling of the catalogx/v1/quotes REST endpoint. The handler loaded any WooCommerce order by its ID, set it to the 'Rejected Quote' status and replaced its customer note with the supplied text, without checking that the order was a quote or that it belonged to the requester. This makes it possible for unauthenticated attackers to move arbitrary orders, including paid orders, to the 'Rejected Quote' status and overwrite their customer notes when the Quote module is enabled and quote requests are open to everyone, which is the default. When quote requests are restricted to logged-in users, a customer-level account is required.
References
- https://wpsec.com/vuln/WPSEC-2026-0578/
- https://plugins.svn.wordpress.org/woocommerce-catalog-enquiry/tags/6.1.6/
- https://wordpress.org/plugins/woocommerce-catalog-enquiry/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS