Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4432

22
FAUCET Score

CVE-2026-4432 affects the YITH WooCommerce Wishlist WordPress plugin versions prior to 4.13.0, stemming from insufficient access controls in the save_title() AJAX handler. The vulnerability allows unauthenticated attackers to rename any wishlist on a site by exploiting a publicly exposed nonce token found in the page source of the /wishlist/ page. The plugin fails to validate actual wishlist ownership before processing rename requests, creating a direct access control weakness. The vulnerability carries a CVSS score of 6.5 (Medium) with an attack vector requiring only network access and no special privileges or user interaction. While the potential impact includes unauthorized modification of wishlist data and partial information disclosure, the exploit requires minimal complexity and can be executed by unauthenticated users. The FAUCET risk score of 35.0 and EPSS score of 0.0004 indicate relatively low comparative risk across the broader CVE landscape. There is currently no evidence of active exploitation, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The straightforward nature of the attack and public nonce exposure suggest that exploitation would be relatively trivial if threat actors chose to target this vulnerability, though community attention remains limited at this time. Organizations running YITH WooCommerce Wishlist should upgrade to version 4.13.0 or later to remediate this access control flaw.

Impacted Technologies

VendorProductVersion(s)CPE
UnknownYITH WooCommerce Wishlist
>= 0, < 4.13.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 5th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

wpscan.com / vulnerability/2f052086-b691-48df-9b08-2cb1db65e14e