The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to extract data from wishlists that they should not have access to.
References
Configurations
History
04 Feb 2025, 18:47
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:moreconvert:woocommerce_wishlist:*:*:*:*:*:wordpress:*:* | |
First Time |
Moreconvert
Moreconvert woocommerce Wishlist |
|
CWE | CWE-639 | |
Summary |
|
|
References | () https://plugins.trac.wordpress.org/browser/smart-wishlist-for-more-convert/trunk/includes/class-wlfmc-form-handler.php#L607 - Product | |
References | () https://plugins.trac.wordpress.org/browser/smart-wishlist-for-more-convert/trunk/includes/class-wlfmc-wishlist.php#L529 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3229758/ - Patch | |
References | () https://wordpress.org/plugins/smart-wishlist-for-more-convert/#developers - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/59fe7630-ab94-419f-aca5-39b74d86ae4e?source=cve - Third Party Advisory |
30 Jan 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-30 09:15
Updated : 2025-02-04 18:47
NVD link : CVE-2024-13694
Mitre link : CVE-2024-13694
CVE.ORG link : CVE-2024-13694
JSON object : View
Products Affected
moreconvert
- woocommerce_wishlist