CVE-2025-12040
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12040 is an Insecure Direct Object Reference (IDOR) vulnerability in the Wishlist for WooCommerce WordPress plugin by ThemeHunk. It affects all versions up to and including 1.1.3, allowing unauthenticated attackers to modify other users' wishlists by exploiting missing validation on a user-controlled key in class-th-wishlist-frontend.php. The vulnerability was published on November 25, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). Several functions within class-th-wishlist-frontend.php accept a user-supplied key to identify and operate on wishlist objects without validating that the requesting user is authorized to access or modify the targeted wishlist. Because no server-side ownership check is performed, an unauthenticated attacker can supply an arbitrary wishlist identifier in a network request to manipulate any user's wishlist data (Wordfence, Red Hat CVE).

Impact

Successful exploitation allows unauthenticated remote attackers to read and modify other users' wishlist data, resulting in limited confidentiality and integrity impacts. Attackers could enumerate wishlist contents (revealing product preferences or saved items) and alter or delete wishlist entries belonging to any registered user. Availability is not directly affected, and the vulnerability does not provide a path to remote code execution or lateral movement beyond the wishlist feature (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.027%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication, no user interaction, and low complexity, making it straightforward to exploit if an attacker targets the plugin (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Wishlist for WooCommerce plugin (version ≤ 1.1.3) by checking plugin metadata in page source, HTTP headers, or using tools like WPScan.
  2. Enumerate wishlist keys: Send unauthenticated requests to the plugin's frontend endpoints (functions in class-th-wishlist-frontend.php) with sequentially or randomly guessed wishlist identifiers to discover valid keys belonging to other users.
  3. Craft malicious request: Construct an HTTP request (GET or POST, depending on the targeted function) supplying a discovered wishlist key as the user-controlled parameter without any authentication token.
  4. Modify target wishlist: The server processes the request without ownership validation, allowing the attacker to add, remove, or alter items in the victim user's wishlist.
  5. Exfiltrate data: Read the response to obtain the victim's wishlist contents, potentially revealing saved product preferences or personal shopping data (Wordfence).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to WordPress AJAX endpoints or REST API routes associated with the th-wishlist plugin, particularly with varying or sequential wishlist key parameters.
  • Logs: WordPress access logs showing repeated requests to wishlist-related endpoints (/?wc-ajax=, /wp-admin/admin-ajax.php) from a single IP without a valid session cookie, especially with differing wishlist ID values.
  • File System: No file-system artifacts expected from this vulnerability, as exploitation is purely request-based with no file writes involved.

Mitigation and workarounds

Users should update the Wishlist for WooCommerce plugin to version 1.1.0 or later (the fix was introduced in 1.1.0), which adds proper server-side validation of the user-controlled wishlist key. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting access to wishlist endpoints via a web application firewall rule. Site administrators can monitor access logs for anomalous unauthenticated requests to wishlist endpoints as a compensating control (Wordfence, WordPress Plugin).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for November 24–30, 2025, noting it as a network-accessible IDOR with no privileges required (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the standard disclosure has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management