CVE-2026-27329
YITH WooCommerce Wishlist
Minimum safe version
4.13.0
Update to 4.13.0 or later to address 13 fixable vulnerabilities
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename
YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Insecure Direct Object Reference to Wishlist Rename
CVE-2025-12777
CVE-2025-12427
WordPress YITH WooCommerce Wishlist Plugin <= 4.5.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-34385
YITH WooCommerce Wishlist <= 2.1.2 - SQL Injection
YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
WordPress YITH WooCommerce Wishlist Plugin <= 3.14.0 is vulnerable to Cross Site Request Forgery (CSRF)
YITH WooCommerce Wishlist <= 2.1.2 - Authenticated SQL Injection
WordPress YITH WooCommerce Wishlist plugin <=2.1.2 - Authenticated SQL Injection (SQLi) vulnerability
CVE-2019-16251