CVE-2025-11532

MEDIUM

Wisly plugin - Insecure Direct Object Reference

Title source: llm
STIX 2.1

Description

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on the 'wishlist_id' user controlled key. This makes it possible for unauthenticated attackers to remove and add items to other user's wishlists.

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
softivus/Wisly < 1.0.0
Published Nov 11, 2025
Tracked Since Feb 18, 2026