CVE-2026-4432 affects the YITH WooCommerce Wishlist WordPress plugin versions prior to 4.13.0, stemming from insufficient access controls in the save_title() AJAX handler. The vulnerability allows unauthenticated attackers to rename any wishlist on a site by exploiting a publicly exposed nonce token found in the page source of the /wishlist/ page. The plugin fails to validate actual wishlist ownership before processing rename requests, creating a direct access control weakness. The vulnerability carries a CVSS score of 6.5 (Medium) with an attack vector requiring only network access and no special privileges or user interaction. While the potential impact includes unauthorized modification of wishlist data and partial information disclosure, the exploit requires minimal complexity and can be executed by unauthenticated users. The FAUCET risk score of 35.0 and EPSS score of 0.0004 indicate relatively low comparative risk across the broader CVE landscape. There is currently no evidence of active exploitation, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The straightforward nature of the attack and public nonce exposure suggest that exploitation would be relatively trivial if threat actors chose to target this vulnerability, though community attention remains limited at this time. Organizations running YITH WooCommerce Wishlist should upgrade to version 4.13.0 or later to remediate this access control flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Unknown | YITH WooCommerce Wishlist | >= 0, < 4.13.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.