CVE-2025-32272: WordPress Wishlist plugin <= 1.0.46 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist allows Cross Site Request Forgery. This issue affects Wishlist: from n/a through 1.0.44.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist wishlist allows Cross Site Request Forgery.This issue affects Wishlist: from n/a through <= 1.0.46.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32272?
CVE-2025-32272 is classified as a critical Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-32272?
To fix CVE-2025-32272, update the PickPlugins Wishlist plugin to a version higher than 1.0.44.
What versions are affected by CVE-2025-32272?
CVE-2025-32272 affects PickPlugins Wishlist versions from n/a through 1.0.44.
What type of attack does CVE-2025-32272 involve?
CVE-2025-32272 involves a Cross-Site Request Forgery (CSRF) attack.
Is CVE-2025-32272 specific to any platforms?
CVE-2025-32272 is specific to the PickPlugins Wishlist and the WordPress Wishlist Plugin.