# CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce <= 6.1.5 - Unauthenticated Insecure Direct Object Reference to Arbitrary Order Status Modification via 'orderId' Parameter

- **ID:** WPSEC-2026-0578
- **Plugin:** CatalogX Product Catalog, Product Enquiry & Quotes for WooCommerce (`woocommerce-catalog-enquiry`), https://wordpress.org/plugins/woocommerce-catalog-enquiry/
- **Affected versions:** from 6.0.0 before 6.1.6
- **Fixed in:** 6.1.6 (Update to 6.1.6 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-catalog-enquiry
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0578/

## Description

The CatalogX - Catalog Mode, Enquiry & Quotes for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 6.0.0 up to, and including, 6.1.5 due to missing validation on the user-controlled 'orderId' parameter in the quote rejection handling of the catalogx/v1/quotes REST endpoint. The handler loaded any WooCommerce order by its ID, set it to the 'Rejected Quote' status and replaced its customer note with the supplied text, without checking that the order was a quote or that it belonged to the requester. This makes it possible for unauthenticated attackers to move arbitrary orders, including paid orders, to the 'Rejected Quote' status and overwrite their customer notes when the Quote module is enabled and quote requests are open to everyone, which is the default. When quote requests are restricted to logged-in users, a customer-level account is required.

## References

- https://wpsec.com/vuln/WPSEC-2026-0578/
- https://plugins.svn.wordpress.org/woocommerce-catalog-enquiry/tags/6.1.6/
- https://wordpress.org/plugins/woocommerce-catalog-enquiry/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0578/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
