PT-2026-94082 · Prestashop+1 · Blockwishlist

·

CVE-2026-92810

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PrestaShop blockwishlist versions prior to 3.0.3
Description Authenticated customers can retrieve share tokens for any wishlist by providing sequential identifiers. This occurs because the getUrlByIdWishListAction() function fails to validate wishlist ownership, enabling unauthorized access to the private wishlist contents of other customers.
Recommendations Update PrestaShop blockwishlist to version 3.0.3 or later. As a temporary workaround, restrict access to the getUrlByIdWishListAction() function.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92810

Affected Products

Blockwishlist