
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12040 is an Insecure Direct Object Reference (IDOR) vulnerability in the Wishlist for WooCommerce WordPress plugin by ThemeHunk. It affects all versions up to and including 1.1.3, allowing unauthenticated attackers to modify other users' wishlists by exploiting missing validation on a user-controlled key in class-th-wishlist-frontend.php. The vulnerability was published on November 25, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). Several functions within class-th-wishlist-frontend.php accept a user-supplied key to identify and operate on wishlist objects without validating that the requesting user is authorized to access or modify the targeted wishlist. Because no server-side ownership check is performed, an unauthenticated attacker can supply an arbitrary wishlist identifier in a network request to manipulate any user's wishlist data (Wordfence, Red Hat CVE).
Successful exploitation allows unauthenticated remote attackers to read and modify other users' wishlist data, resulting in limited confidentiality and integrity impacts. Attackers could enumerate wishlist contents (revealing product preferences or saved items) and alter or delete wishlist entries belonging to any registered user. Availability is not directly affected, and the vulnerability does not provide a path to remote code execution or lateral movement beyond the wishlist feature (Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.027%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication, no user interaction, and low complexity, making it straightforward to exploit if an attacker targets the plugin (Wordfence, Red Hat CVE).
class-th-wishlist-frontend.php) with sequentially or randomly guessed wishlist identifiers to discover valid keys belonging to other users.th-wishlist plugin, particularly with varying or sequential wishlist key parameters./?wc-ajax=, /wp-admin/admin-ajax.php) from a single IP without a valid session cookie, especially with differing wishlist ID values.Users should update the Wishlist for WooCommerce plugin to version 1.1.0 or later (the fix was introduced in 1.1.0), which adds proper server-side validation of the user-controlled wishlist key. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting access to wishlist endpoints via a web application firewall rule. Site administrators can monitor access logs for anomalous unauthenticated requests to wishlist endpoints as a compensating control (Wordfence, WordPress Plugin).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for November 24–30, 2025, noting it as a network-accessible IDOR with no privileges required (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the standard disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."