The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to modify/update/create other user's wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
History

Fri, 21 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpdesk
Wpdesk flexible Wishlist For Woocommerce
CPEs cpe:2.3:a:wpdesk:flexible_wishlist_for_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpdesk
Wpdesk flexible Wishlist For Woocommerce

Tue, 18 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Feb 2025 08:30:00 +0000

Type Values Removed Values Added
Description The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to modify/update/create other user's wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-18T14:36:33.225Z

Reserved: 2025-01-24T15:35:10.684Z

Link: CVE-2024-13718

cve-icon Vulnrichment

Updated: 2025-02-18T14:36:29.528Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-18T09:15:09.723

Modified: 2025-02-21T15:25:03.847

Link: CVE-2024-13718

cve-icon Redhat

No data.