Cross-Site Request Forgery Vulnerability in Wishlist for WooCommerce Plugin by WordPress
CVE-2024-13774

6.5MEDIUM

What is CVE-2024-13774?

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress has a vulnerability allowing Cross-Site Request Forgery (CSRF) attacks in all versions up to and including 3.1.7. This weakness stems from inadequate nonce validation in the ‘save_to_multiple_wishlist’ function, enabling attackers to exploit the vulnerability by tricking site administrators into making unwanted actions. By leveraging this flaw, unauthorized users could modify plugin settings or inject harmful scripts into the website, potentially leading to significant security breaches.

Affected Version(s)

Wishlist for WooCommerce: Multi Wishlists Per Customer * <= 3.1.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.