plugin

Qode Wishlist For Woocommerce Vulnerabilities

1 known security issue reported for the Qode Wishlist For Woocommerce WordPress plugin. Most recent disclosed Nov 26, 2025.

1 medium

Running Qode Wishlist For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

QODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishlist Update

medium

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for unauthenticate...

CVSS:
5.3
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Nov 26, 2025

CVE-2025-13157 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database