High 7.2
2026-02-19< 3.7.0
CVE-2026-22333
Minimum safe version
3.7.0
Update to 3.7.0 or later to address 9 fixable vulnerabilities
CVE-2026-22333
CVE-2024-32699
YITH WooCommerce Compare <= 2.0.9 - Unauthenticated PHP Object Injection
YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
WordPress YITH WooCommerce Compare Plugin <= 2.20.0 is vulnerable to Cross Site Request Forgery (CSRF)
YITH WooCommerce Compare <= 2.0.9 - Unauthenticated PHP Object injection
WordPress YITH WooCommerce Compare Plugin <= 2.0.9 - PHP Object injection
CVE-2019-16251