Junglewise Threat Intelligence

CVE-2026-4432: YITH WooCommerce Wishlist IDOR in save_title AJAX handler

CVE-2026-4432 · Severity: medium · CVSS 6.5 · Published 2026-04-10

Vendors: YITH.

Executive brief

A vulnerability in the YITH WooCommerce Wishlist plugin for WordPress allows unauthorized individuals to rename any user's wishlist. This plugin is used by e-commerce sites to let customers save products for later purchase. An attacker could exploit this to deface customer accounts or disrupt the shopping experience by changing wishlist titles without permission.

Technical details

The YITH WooCommerce Wishlist plugin suffers from an Insecure Direct Object Reference (IDOR) vulnerability within its `save_title()` AJAX handler. The function fails to perform authorization checks to ensure the requesting user owns the target wishlist, instead relying solely on a security nonce that is publicly exposed in the source code of the /wishlist/ page. An unauthenticated attacker can obtain this nonce and send a crafted POST request to `admin-ajax.php` with a target `wishlist_id` to rename any wishlist on the site. This issue is resolved in version 4.13.0.

Affected products

  • YITH YITH WooCommerce Wishlist < 4.13.0

Timeline

  • 2026-03-20: disclosed: Publicly published by WPScan
  • 2026-04-10: advisory: NVD advisory published

References