PT-2026-31882 · WordPress · Yith Woocommerce Wishlist

Chiao-Lin Yu

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-4432

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions YITH WooCommerce Wishlist WordPress plugin versions prior to 4.13.0
Description The YITH WooCommerce Wishlist WordPress plugin does not properly validate wishlist ownership in the save title() AJAX handler when renaming wishlists. The function only verifies a nonce, which is publicly available, allowing unauthenticated attackers to rename any user's wishlist.
Recommendations Update to version 4.13.0 or later.

Exploit

Fix

Related Identifiers

CVE-2026-4432

Affected Products

Yith Woocommerce Wishlist