PT-2025-46564 · Unknown+1 · Woocommerce+1

Itthidej Aramsri

·

Published

2025-11-12

·

Updated

2025-11-12

·

CVE-2025-12087

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Wishlist and Save for later for Woocommerce plugin for WordPress versions through 1.1.22
Description The software contains an Insecure Direct Object Reference issue. An authenticated attacker with Subscriber-level access or higher can delete wishlist items belonging to other users. This is due to a lack of validation on a user-controlled key within the awwlm remove added wishlist page AJAX action.
Recommendations Update The Wishlist and Save for later for Woocommerce plugin for WordPress to a version later than 1.1.22.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-12087

Affected Products

Wishlist/Save For Later For Woocommerce
Woocommerce