← WordPress Vulnerabilities
WordPress security by component

YITH WooCommerce Wishlist

YITH WooCommerce Wishlist adds wishlist functionality to WooCommerce stores, allowing shoppers to save and manage products for later.

YITH WooCommerce Wishlist (yith-woocommerce-wishlist) is a WordPress plugin with 8 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.5.

Plugin slug: yith-woocommerce-wishlist

CVE-2026-82305: YITH WooCommerce Wishlist allows unauthenticated renaming

YITH WooCommerce Wishlist before 4.18.1 does not verify that the caller is authorized to rename the requested wishlist. An unauthenticated attacker can rename any wishlist on the site. The authoritative export does not identify the endpoint, action, wishlist identifier, or name parameter.

PublishedSep 11, 2026
Known safe version4.18.1
Published vulnerabilities for yith-woocommerce-wishlist
Safe version
Sep 11, 2026 CVE-2026-82305
YITH WooCommerce Wishlist allows unauthenticated renaming
YITH WooCommerce Wishlist before 4.18.1 does not verify that the caller is authorized to rename the requested wishlist. An unauthenticated attacker can rename any wishlist on the site. The authoritative export does not identify the endpoint, action, wishlist identifier, or name parameter.
4.18.1
CVE5.3
NVDPending
May 07, 2026 CVE-2026-27329
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.12.0.
4.13.0
CVE5.3
NVDPending
Apr 10, 2026 CVE-2026-4432
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.13.0.
4.13.0
CVE6.5
NVDPending
Nov 19, 2025 CVE-2025-12777
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 19, 2025 CVE-2025-12427
YITH WooCommerce Wishlist: Broken access control
YITH WooCommerce Wishlist is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE5.3
NVDPending
Jun 14, 2025 CVE-2025-5238
YITH WooCommerce Wishlist: Cross-site scripting
YITH WooCommerce Wishlist is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jun 03, 2024 CVE-2024-34385
YITH WooCommerce Wishlist: Cross-site scripting
YITH WooCommerce Wishlist is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Oct 31, 2019 CVE-2019-16251
Yith Woocommerce Wishlist: A security weakness
Yith Woocommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3