Description
The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to update the public view of arbitrary wishlists.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
* (semver)
Timeline
| 2025-11-13: | Vendor Notified |
| 2025-11-26: | Disclosed |
Credits
Athiwat Tiprasaharn
Powpy
Peerapat Samatathanyakorn
References
www.wordfence.com/...-ecf9-4253-b832-056b34f42b48?source=cve
plugins.trac.wordpress.org/...wishlist-table/helper-ajax.php
plugins.trac.wordpress.org/changeset/3402469/