WordPress security by component
YITH WooCommerce Wishlist
Plugin description
YITH WooCommerce Wishlist adds wishlist functionality to WooCommerce stores, allowing shoppers to save and manage products for later.
YITH WooCommerce Wishlist (yith-woocommerce-wishlist) is a WordPress plugin with 8 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
yith-woocommerce-wishlistLatest vulnerability
CVE-2026-82305: YITH WooCommerce Wishlist allows unauthenticated renaming
YITH WooCommerce Wishlist before 4.18.1 does not verify that the caller is authorized to rename the requested wishlist. An unauthenticated attacker can rename any wishlist on the site. The authoritative export does not identify the endpoint, action, wishlist identifier, or name parameter.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-82305
YITH WooCommerce Wishlist allows unauthenticated renaming
YITH WooCommerce Wishlist before 4.18.1 does not verify that the caller is authorized to rename the requested wishlist. An unauthenticated attacker can rename any wishlist on the site. The authoritative export does not identify the endpoint, action, wishlist identifier, or name parameter.
|
4.18.1 |
CVE5.3
NVDPending
|
| May 07, 2026 |
CVE-2026-27329
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.12.0.
|
4.13.0 |
CVE5.3
NVDPending
|
| Apr 10, 2026 |
CVE-2026-4432
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.13.0.
|
4.13.0 |
CVE6.5
NVDPending
|
| Nov 19, 2025 |
CVE-2025-12777
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 19, 2025 |
CVE-2025-12427
YITH WooCommerce Wishlist: Broken access control
YITH WooCommerce Wishlist is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 14, 2025 |
CVE-2025-5238
YITH WooCommerce Wishlist: Cross-site scripting
YITH WooCommerce Wishlist is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jun 03, 2024 |
CVE-2024-34385
YITH WooCommerce Wishlist: Cross-site scripting
YITH WooCommerce Wishlist is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Oct 31, 2019 |
CVE-2019-16251
Yith Woocommerce Wishlist: A security weakness
Yith Woocommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|