The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to extract data from wishlists that they should not have access to.
History

Tue, 04 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Moreconvert
Moreconvert woocommerce Wishlist
Weaknesses CWE-639
CPEs cpe:2.3:a:moreconvert:woocommerce_wishlist:*:*:*:*:*:wordpress:*:*
Vendors & Products Moreconvert
Moreconvert woocommerce Wishlist

Thu, 30 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 08:30:00 +0000

Type Values Removed Values Added
Description The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to extract data from wishlists that they should not have access to.
Title WooCommerce Wishlist <= 1.8.7 - Unauthenticated Wishlist Disclosure via download_pdf_file Function
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-01-30T15:06:26.871Z

Reserved: 2025-01-23T20:53:30.253Z

Link: CVE-2024-13694

cve-icon Vulnrichment

Updated: 2025-01-30T15:05:59.503Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-30T09:15:08.180

Modified: 2025-02-04T18:47:41.800

Link: CVE-2024-13694

cve-icon Redhat

No data.