Insecure Direct Object Reference in WooCommerce Wishlist Plugin by WordPress
CVE-2024-13694
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 January 2025
What is CVE-2024-13694?
The WooCommerce Wishlist plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability that affects all versions up to and including 1.8.7. The flaw exists in the download_pdf_file() function, where absent validation on a user-controlled key permits unauthenticated attackers to potentially access and extract sensitive data from user wishlists. This vulnerability highlights the importance of proper input validation and security measures in web applications to prevent unauthorized data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) * <= 1.8.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved