Medium 6.4
2025-12-13< 2.7.1
YITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode
Minimum safe version
2.7.1
Update to 2.7.1 or later to address 5 fixable vulnerabilities
YITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode
YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
WordPress YITH WooCommerce Quick View Plugin <= 1.21.0 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2019-16251