CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce <= 6.1.5 - Unauthenticated Insecure Direct Object Reference to Arbitrary Order Status Modification via 'orderId' Parameter

Medium 5.3 CWE-639Fixed in 6.1.6
ID
WPSEC-2026-0578
Plugin
CatalogX Product Catalog, Product Enquiry & Quotes for WooCommerce (woocommerce-catalog-enquiry)
Affected
from 6.0.0 before 6.1.6
Remediation
Update to 6.1.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The CatalogX - Catalog Mode, Enquiry & Quotes for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 6.0.0 up to, and including, 6.1.5 due to missing validation on the user-controlled 'orderId' parameter in the quote rejection handling of the catalogx/v1/quotes REST endpoint. The handler loaded any WooCommerce order by its ID, set it to the 'Rejected Quote' status and replaced its customer note with the supplied text, without checking that the order was a quote or that it belonged to the requester. This makes it possible for unauthenticated attackers to move arbitrary orders, including paid orders, to the 'Rejected Quote' status and overwrite their customer notes when the Quote module is enabled and quote requests are open to everyone, which is the default. When quote requests are restricted to logged-in users, a customer-level account is required.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0