Cross-Site Request Forgery Vulnerability in Wishlist for WooCommerce Plugin by WordPress
CVE-2024-13774

6.1MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
8 March 2025

Summary

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress has a vulnerability allowing Cross-Site Request Forgery (CSRF) attacks in all versions up to and including 3.1.7. This weakness stems from inadequate nonce validation in the ‘save_to_multiple_wishlist’ function, enabling attackers to exploit the vulnerability by tricking site administrators into making unwanted actions. By leveraging this flaw, unauthorized users could modify plugin settings or inject harmful scripts into the website, potentially leading to significant security breaches.

Affected Version(s)

Wishlist for WooCommerce: Multi Wishlists Per Customer * <= 3.1.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.