CVE-2025-11518
MEDIUMWPC Smart Wishlist <5.0.3 - Insecure Direct Object Reference
Title source: llmDescription
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unauthenticated attackers to empty and add to other user's wishlists, if they have access to the key.
References (2)
Core 2
Core References
Scores
CVSS v3
5.3
EPSS
0.0006
EPSS Percentile
20.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
wpclever/WPC Smart Wishlist for WooCommerce
< 5.0.3
Published
Oct 11, 2025
Tracked Since
Feb 18, 2026