CVE-2026-92810: Authorization Bypass Through User-Controlled Key in PrestaShop blockwishlist
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.
AI Analysis
Technical Summary
PrestaShop blockwishlist versions through 3.0.2 contain an authorization bypass vulnerability in the getUrlByIdWishListAction method. The module fails to validate wishlist ownership properly, allowing authenticated users to supply sequential wishlist identifiers to retrieve valid share tokens. This flaw permits unauthorized reading of other customers' private wishlist contents by exploiting the lack of ownership verification.
Potential Impact
An attacker with authenticated access can enumerate wishlist identifiers and obtain share tokens for wishlists they do not own. This leads to unauthorized disclosure of private wishlist data belonging to other customers. The vulnerability does not require user interaction and has a low complexity of attack but requires authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the blockwishlist module to trusted users only and monitor for unusual access patterns. Avoid sharing wishlist identifiers publicly.
CVE-2026-92810: Authorization Bypass Through User-Controlled Key in PrestaShop blockwishlist
Description
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.
CVSS v4.0
Score 5.3medium
Affected software
PrestaShop
blockwishlist
pkg:github/prestashop/blockwishlistRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PrestaShop blockwishlist versions through 3.0.2 contain an authorization bypass vulnerability in the getUrlByIdWishListAction method. The module fails to validate wishlist ownership properly, allowing authenticated users to supply sequential wishlist identifiers to retrieve valid share tokens. This flaw permits unauthorized reading of other customers' private wishlist contents by exploiting the lack of ownership verification.
Potential Impact
An attacker with authenticated access can enumerate wishlist identifiers and obtain share tokens for wishlists they do not own. This leads to unauthorized disclosure of private wishlist data belonging to other customers. The vulnerability does not require user interaction and has a low complexity of attack but requires authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the blockwishlist module to trusted users only and monitor for unusual access patterns. Avoid sharing wishlist identifiers publicly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-16T19:55:00.980Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aab006555bf5e2cf5231ff0
Added to database: 09/16/2026, 20:47:33 UTC
Last enriched: 09/16/2026, 21:32:47 UTC
Last updated: 09/17/2026, 02:02:50 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.