CVE-2026-4432

CVE-2026-4432: YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR

Vendor Unknown
Product YITH WooCommerce Wishlist
Published April 10, 2026
Last update April 10, 2026

CVSS base score

What the vulnerability does

Description

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible for unauthenticated attackers to rename any wishlist belonging to any user on the site.

Key dates

Disclosure timeline

April 10, 2026 CVE published
April 10, 2026 Record updated