PT-2025-41649 · WordPress · Wpc Smart Wishlist For Woocommerce

·

CVE-2025-11518

·

Publicado

2025-10-11

·

Atualizado

2025-10-11

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPC Smart Wishlist for WooCommerce plugin for WordPress versions up to and including 5.0.3
Description The software is susceptible to an Insecure Direct Object Reference issue in several wishlist AJAX functions. This is due to a lack of validation on a user-controlled key that is exposed when wishlists are shared. This allows unauthenticated attackers to manipulate other users' wishlists, including adding items and emptying them, if they have access to the key.
Recommendations Update the WPC Smart Wishlist for WooCommerce plugin to a version later than 5.0.3.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-11518

Produtos afetados

Wpc Smart Wishlist For Woocommerce