The YITH Request a Quote for WooCommerce plugin for WordPress is vulnerable to malicious attacks in versions up to, and including, 1.6.3. This is because it does not have enough protection to stop unauthorized users from adding or changing items in a quote. To do this, a person would need to trick a user of the site into clicking a link.