Description
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The blockwishlist module up to version 3.0.2 fails to enforce ownership checks in its getUrlByIdWishListAction logic, allowing authenticated users to request a share token for any wishlist identifier. This enables attackers to read other customers' private wishlists by enumerating identifiers.

Affected Systems

The vulnerability affects installations of the PrestaShop blockwishlist module version 3.0.2 or earlier. Users of the module within any PrestaShop instance should verify that the module is upgraded past this version.

Risk and Exploitability

The CVSS score of 5.3 classifies it as a medium severity information disclosure. The EPSS score of less than 1% indicates that, as of current data, the likelihood of exploitation is low. The issue is not listed in CISA’s KEV catalog, and the attack requires an authenticated account and sequential wishlist IDs, which reduces the exposure compared to a publicly exploitable flaw.

Generated by OpenCVE AI on September 17, 2026 at 22:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the PrestaShop blockwishlist module to the latest release that enforces wishlist ownership checks.
  • If an upgrade cannot be performed immediately, disable or remove the getUrlByIdWishListAction endpoint to block share token requests.
  • Audit other optional modules for similar missing authorization checks and ensure that any endpoint exposing user data validates ownership before processing requests.

Generated by OpenCVE AI on September 17, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.
Title PrestaShop blockwishlist through 3.0.2 Information Disclosure
First Time appeared Prestashop
Prestashop blockwishlist
Weaknesses CWE-639
CPEs cpe:2.3:a:prestashop:blockwishlist:*:*:*:*:*:*:*:*
Vendors & Products Prestashop
Prestashop blockwishlist
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Prestashop Blockwishlist
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:56:49.832Z

Reserved: 2026-09-16T19:55:00.980Z

Link: CVE-2026-92810

cve-icon Vulnrichment

Updated: 2026-09-17T14:56:45.631Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:30.723

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:45:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key