Cross-Site Request Forgery Vulnerability in Wishlist for WooCommerce Plugin by WordPress
CVE-2024-13774
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-13774?
The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress has a vulnerability allowing Cross-Site Request Forgery (CSRF) attacks in all versions up to and including 3.1.7. This weakness stems from inadequate nonce validation in the âsave_to_multiple_wishlistâ function, enabling attackers to exploit the vulnerability by tricking site administrators into making unwanted actions. By leveraging this flaw, unauthorized users could modify plugin settings or inject harmful scripts into the website, potentially leading to significant security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wishlist for WooCommerce: Multi Wishlists Per Customer * <= 3.1.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved