CVE · Medium

CVE-2025-12427 — YITH WooCommerce Wishlist [yith-woocommerce-wishlist] <= 4.10.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12427 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] <= 4.10.0 (unfixed) Authorization Bypass Through User-Controlled Key Medium 5.3 < 4.10.0 4.10.0 2025-11-18

CVE-2025-12427

A vulnerability in YITH WooCommerce Wishlist plugin affects all versions up to 4.10.0, allowing unauthorized access to user-controlled keys through the REST API endpoint or AJAX handler. This flaw enables attackers to uncover wishlist token IDs of any user, ultimately permitting them to alter a victim's wishlist without permission.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.