The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to extract data from wishlists that they should not have access to.
                
            References
                    Configurations
                    History
                    04 Feb 2025, 18:47
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:moreconvert:woocommerce_wishlist:*:*:*:*:*:wordpress:*:* | |
| First Time | Moreconvert Moreconvert woocommerce Wishlist | |
| CWE | CWE-639 | |
| Summary | 
 | |
| References | () https://plugins.trac.wordpress.org/browser/smart-wishlist-for-more-convert/trunk/includes/class-wlfmc-form-handler.php#L607 - Product | |
| References | () https://plugins.trac.wordpress.org/browser/smart-wishlist-for-more-convert/trunk/includes/class-wlfmc-wishlist.php#L529 - Product | |
| References | () https://plugins.trac.wordpress.org/changeset/3229758/ - Patch | |
| References | () https://wordpress.org/plugins/smart-wishlist-for-more-convert/#developers - Product | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/59fe7630-ab94-419f-aca5-39b74d86ae4e?source=cve - Third Party Advisory | 
30 Jan 2025, 09:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-01-30 09:15
Updated : 2025-02-04 18:47
NVD link : CVE-2024-13694
Mitre link : CVE-2024-13694
CVE.ORG link : CVE-2024-13694
JSON object : View
Products Affected
                moreconvert
- woocommerce_wishlist
