Insecure Direct Object Reference Vulnerability in Wisly Plugin for WordPress
CVE-2025-11532
5.3MEDIUM
What is CVE-2025-11532?
The Wisly plugin for WordPress contains an Insecure Direct Object Reference vulnerability due to insufficient validation of the 'wishlist_id' user-controlled key. This flaw allows unauthenticated attackers to manipulate other users' wishlists by adding or removing items without authorization, posing a significant risk to user data integrity and privacy.
Affected Version(s)
Wisly * <= 1.0.0