Impact
The YITH WooCommerce Wishlist WordPress plugin before version 4.18.1 does not verify that a user is authorized to rename a wishlist. This allows anyone, even unauthenticated visitors, to change the title of any wishlist on a site. The flaw does not provide code execution or privilege escalation, but it can be used, or facilitate social‑engineering or phishing attempts. The underlying weakness is an authorization bypass (CWE-639).
Affected Systems
All WordPress sites running the YITH WooCommerce Wishlist plugin older than 4.18.1 are affected. Any installation of the plugin before the cumulative release 4.18.1 is vulnerable, regardless of minor sub‑versions.
Risk and Exploitability
An attacker can exploit the flaw by sending a simple unauthenticated HTTP request to the change_wishlist_title endpoint, providing a wishlist ID and a new title. The CVSS score of 5.3 reflects a moderate severity that affects data integrity. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the low attack barrier means that any site with the vulnerable plugin should be considered at risk until the fix is applied.
OpenCVE Enrichment