CVE-2025-11518: WPC Smart Wishlist for WooCommerce <= 5.0.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unauthenticated attackers to empty and add to other user's wishlists, if they have access to the key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11518?
CVE-2025-11518 is rated as a high severity vulnerability due to its potential for unauthorized access to user wishlists.
How do I fix CVE-2025-11518?
To fix CVE-2025-11518, update the WPC Smart Wishlist for WooCommerce plugin to version 5.0.4 or later.
What types of attacks can exploit CVE-2025-11518?
CVE-2025-11518 can be exploited through unauthorized viewing or modification of user wishlists via insecure AJAX requests.
Which versions of the WPC Smart Wishlist for WooCommerce are affected by CVE-2025-11518?
All versions of the WPC Smart Wishlist for WooCommerce plugin up to and including 5.0.3 are affected by CVE-2025-11518.
What are the implications of CVE-2025-11518 for users of the plugin?
Users of the plugin may face data leakage and exposure of sensitive wishlist information due to improper access controls.