WordPress security by component
YITH WooCommerce Wishlist
Plugin description
YITH WooCommerce Wishlist is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published May 07, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
yith-woocommerce-wishlistLatest vulnerability
CVE-2026-27329: YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.12.0.
| Safe version |
|
||
|---|---|---|---|
| May 07, 2026 |
CVE-2026-27329
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.12.0.
|
4.13.0 |
CVE5.3
NVDPending
|
| Apr 10, 2026 |
CVE-2026-4432
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.13.0.
|
4.13.0 |
CVE6.5
NVDPending
|
| Nov 19, 2025 |
CVE-2025-12777
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 19, 2025 |
CVE-2025-12427
YITH WooCommerce Wishlist: A security weakness
YITH WooCommerce Wishlist is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 14, 2025 |
CVE-2025-5238
YITH WooCommerce Wishlist: Cross-site scripting
YITH WooCommerce Wishlist is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jun 03, 2024 |
CVE-2024-34385
YITH WooCommerce Wishlist: Cross-site scripting
YITH WooCommerce Wishlist is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Oct 31, 2019 |
CVE-2019-16251
Yith Woocommerce Wishlist: A security weakness
Yith Woocommerce Wishlist is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|