CVE-2025-32272

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 352

Summary

CVE-2025-32272 is a Cross-Site Request Forgery (CSRF) vulnerability affecting PickPlugins Wishlist, a plugin used for managing wishlists on WordPress websites. The flaw permits unauthenticated attackers to submit malicious requests on behalf of a victim, potentially resulting in unintended actions within the plugin. Affected versions range from n/a to 1.0.44. Updating to the latest version or implementing CSRF protection mechanisms is recommended to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share