plugin

Th Wishlist Vulnerabilities

1 known security issue reported for the Th Wishlist WordPress plugin. Most recent disclosed Nov 24, 2025.

1 medium

Running Th Wishlist on your site? Check whether your installed version is affected.

Scan your site free

Wishlist for WooCommerce <= 1.1.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

medium

The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via several functions in class-th-wishlist-frontend.php due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to modify other...

CVSS:
6.5
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Nov 24, 2025

CVE-2025-12040 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database