CVE-2025-12777
The YITH WooCommerce Wishlist plugin for WordPress contains a security flaw in versions prior to 4.10.1, which allows unauthorized users to access sensitive data through the /wp-json/yith/wishlist/v1/lists endpoint due to inadequate permission checks. This vulnerability also enables attackers to delete wishlist items without proper authorization by exploiting a weakness in the AJAX delete_item handler's verification process. As a result, unauthenticated individuals can potentially manipulate shared wishlist pages.
Based on public CVE data (MITRE/NVD).