CVE-2025-12427
Last modified
CVE-2025-12427 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's wishlist token ID, and subsequently rename the victim's wishlist without authorization (integrity impact). EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's wishlist token ID, and subsequently rename the victim's wishlist without authorization (integrity impact). This can be exploited to target multi-user stores for defacement, social engineering attacks, mass tampering, and profiling at scale.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12427?
How severe is CVE-2025-12427?
How do I fix CVE-2025-12427?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12421Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10…9.9
- CVE-2025-12422Vulnerable Upgrade Feature (Arbitrary File Write) may lead t…9.8
- CVE-2025-12423Protocol manipulation might lead to denial of service.This i…7.5
- CVE-2025-12424Privilege Escalation through SUID-bit Binary.This issue affe…9.8
- CVE-2025-12425Local Privilege Escalation.This issue affects BLU-IC2: throu…7.8
- CVE-2025-12426The Quiz Maker plugin for WordPress is vulnerable to Sensiti…7.5
- CVE-2025-12428Type Confusion in V8 in Google Chrome prior to 142.0.7444.59…8.8
- CVE-2025-12429Inappropriate implementation in V8 in Google Chrome prior to…8.8
- CVE-2025-1243The Temporal api-go library prior to version 1.44.1 did not …2
- CVE-2025-12430Object lifecycle issue in Media in Google Chrome prior to 14…7.5
- CVE-2025-12431Inappropriate implementation in Extensions in Google Chrome …6.5
- CVE-2025-12432Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a…8.8
Are you affected by CVE-2025-12427?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
