Impact
The blockwishlist module up to version 3.0.2 fails to enforce ownership checks in its getUrlByIdWishListAction logic, allowing authenticated users to request a share token for any wishlist identifier. This enables attackers to read other customers' private wishlists by enumerating identifiers.
Affected Systems
The vulnerability affects installations of the PrestaShop blockwishlist module version 3.0.2 or earlier. Users of the module within any PrestaShop instance should verify that the module is upgraded past this version.
Risk and Exploitability
The CVSS score of 5.3 classifies it as a medium severity information disclosure. The EPSS score of less than 1% indicates that, as of current data, the likelihood of exploitation is low. The issue is not listed in CISA’s KEV catalog, and the attack requires an authenticated account and sequential wishlist IDs, which reduces the exposure compared to a publicly exploitable flaw.
OpenCVE Enrichment