CVE-2025-32272
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 352
Summary
CVE-2025-32272 is a Cross-Site Request Forgery (CSRF) vulnerability affecting PickPlugins Wishlist, a plugin used for managing wishlists on WordPress websites. The flaw permits unauthenticated attackers to submit malicious requests on behalf of a victim, potentially resulting in unintended actions within the plugin. Affected versions range from n/a to 1.0.44. Updating to the latest version or implementing CSRF protection mechanisms is recommended to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WishList Plugin