Description
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist wishlist allows Cross Site Request Forgery.This issue affects Wishlist: from n/a through <= 1.0.46.
Published: 2025-04-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in the PickPlugins Wishlist plugin for WordPress. The flaw allows a malicious site to craft and submit requests to the plugin’s endpoints and perform actions that the authenticated user would otherwise be required to initiate. Because the plugin does not validate the origin or include a unique nonce, it is possible for an attacker to trigger wishlist modifications, such as adding or removing items, without the user’s consent. No direct disclosure of sensitive data is indicated, but the flaw provides a vector for unauthorized account activity.

Affected Systems

The affected product is the PickPlugins Wishlist plugin for WordPress, versions n/a through 1.0.46. Any WordPress installation that has this plugin in any of those versions and accepts user requests to its wishlist processing routes is vulnerable. Administrators should verify the installed version of the plugin on their sites and consider whether the version falls into the vulnerable range.

Risk and Exploitability

The CVSS score of 4.3 indicates a low overall severity, and the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so there is no known widespread exploitation. The attack vector is inferred to be a remote attacker hosting a malicious webpage that submits a hidden form or makes an AJAX request to the victim’s WordPress site while the victim is authenticated. To successfully exploit the flaw, the victim must already have an active session with the target site and the attacker must be able to submit a crafted request that the plugin will accept.

Generated by OpenCVE AI on May 1, 2026 at 00:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PickPlugins Wishlist plugin to version 1.0.47 or later, which removes the CSRF flaw.
  • Configure any custom wishlist forms to use WordPress nonces, ensuring that state‑changing requests are protected against forgery.
  • If an immediate update is not possible, temporarily disable the Wishlist plugin or restrict unauthenticated access to its endpoints until the patch is applied.

Generated by OpenCVE AI on May 1, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9776 Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist allows Cross Site Request Forgery. This issue affects Wishlist: from n/a through 1.0.44.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist allows Cross Site Request Forgery. This issue affects Wishlist: from n/a through 1.0.44. Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist wishlist allows Cross Site Request Forgery.This issue affects Wishlist: from n/a through <= 1.0.46.
Title WordPress Wishlist Plugin <= 1.0.44 - Cross Site Request Forgery (CSRF) vulnerability WordPress Wishlist plugin <= 1.0.46 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 04 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist allows Cross Site Request Forgery. This issue affects Wishlist: from n/a through 1.0.44.
Title WordPress Wishlist Plugin <= 1.0.44 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:20.372Z

Reserved: 2025-04-04T10:02:30.559Z

Link: CVE-2025-32272

cve-icon Vulnrichment

Updated: 2025-04-04T18:52:24.534Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:38.530

Modified: 2026-04-23T15:28:52.780

Link: CVE-2025-32272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:15:04Z

Weaknesses