PT-2025-42690 · Unknown +1 · Woocommerce +1

Athiwat Tiprasaharn

·

Published

2025-10-18

·

Updated

2025-10-18

·

CVE-2025-11742

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WPC Smart Wishlist for WooCommerce plugin for WordPress versions through 5.0.4
Description The WPC Smart Wishlist for WooCommerce plugin for WordPress is susceptible to unauthorized data access. A missing capability check on the
wishlist quickview
AJAX action allows authenticated attackers with Subscriber-level access or higher to view other users' wishlist data and information. The affected action is
wishlist quickview
.
Recommendations Update the WPC Smart Wishlist for WooCommerce plugin to a version later than 5.0.4.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11742

Affected Products

Wpc Smart Wishlist For Woocommerce
Woocommerce