๐Ÿ” CVE Alert

CVE-2025-13157

MEDIUM 5.3

QODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishlist Update

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to update the public view of arbitrary wishlists.

CWE CWE-639
Vendor qodeinteractive
Product qode wishlist for woocommerce
Published Nov 27, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for qodeinteractive qode wishlist for woocommerce

Be the first to know when new medium vulnerabilities affecting qodeinteractive qode wishlist for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

qodeinteractive / QODE Wishlist for WooCommerce
0 โ‰ค 1.2.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b15d1992-ecf9-4253-b832-056b34f42b48?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/qode-wishlist-for-woocommerce/trunk/inc/wishlist/shortcodes/wishlist-table/helper-ajax.php#L95 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3402469/

Credits

Athiwat Tiprasaharn Powpy Peerapat Samatathanyakorn