CVE-2026-82305

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 07:16

Updated : 2026-09-11 17:35


NVD link : CVE-2026-82305

Mitre link : CVE-2026-82305

CVE.ORG link : CVE-2026-82305


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key