The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. This is due to missing or incorrect nonce validation on the 'save_to_multiple_wishlist' function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Mar 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpfactory
Wpfactory wishlist For Woocommerce |
|
| CPEs | cpe:2.3:a:wpfactory:wishlist_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpfactory
Wpfactory wishlist For Woocommerce |
Mon, 10 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Mar 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. This is due to missing or incorrect nonce validation on the 'save_to_multiple_wishlist' function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.7 - Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-08T02:24:04.980Z
Updated: 2025-03-10T15:57:26.023Z
Reserved: 2025-01-28T17:50:41.058Z
Link: CVE-2024-13774
Updated: 2025-03-10T15:57:22.638Z
Status : Analyzed
Published: 2025-03-08T03:15:36.577
Modified: 2025-03-12T17:01:06.413
Link: CVE-2024-13774
No data.