CVE-2025-11518

MEDIUM

WPC Smart Wishlist <5.0.3 - Insecure Direct Object Reference

Title source: llm
STIX 2.1

Description

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unauthenticated attackers to empty and add to other user's wishlists, if they have access to the key.

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
wpclever/WPC Smart Wishlist for WooCommerce < 5.0.3
Published Oct 11, 2025
Tracked Since Feb 18, 2026