Medium 5.3
2026-01-22< 2.46.1
CVE-2026-24366
Minimum safe version
2.46.1
Update to 2.46.1 or later to address 7 fixable vulnerabilities
CVE-2026-24366
YITH Request a Quote for WooCommerce <= 1.6.3 - Cross-Site Request Forgery
YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
WordPress YITH WooCommerce Request A Quote Plugin <= 2.15.0 is vulnerable to Cross Site Request Forgery (CSRF)
YITH Request a Quote for WooCommerce < 1.6.4 - Unauthorised AJAX call via CSRF
CVE-2019-16251