Executive brief
The YITH WooCommerce Wishlist plugin for WordPress allows unauthenticated attackers to rename any user's wishlists on the site by bypassing authorization checks. An attacker can obtain a public nonce, then rename other users' wishlists without any authentication, potentially causing confusion, disruption, or harassment. This affects e-commerce sites using the plugin to manage customer wish lists.
Technical details
The plugin contains an Insecure Direct Object Reference (IDOR) vulnerability in the wishlist rename functionality (change_wishlist_title action). The vulnerable handler fails to verify that the authenticated user owns or has permission to modify the target wishlist before processing the rename request. An unauthenticated attacker can obtain the edit nonce from the public wishlist page, then send a POST request to change the title and slug of any wishlist on the site by specifying its ID. No authentication cookies or session are required. The vulnerability is fixed in version 4.18.1.
Affected products
- YITH WooCommerce Wishlist before 4.18.1
Timeline
- 2026-09-09: disclosed
- 2026-09-11: patched: Fixed in version 4.18.1