CVE · Medium

CVE-2025-12777 — YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.10.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12777 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.10.1 Improper Authorization Medium 5.3 < 4.10.1 4.10.1 2025-11-18

CVE-2025-12777

The YITH WooCommerce Wishlist plugin for WordPress contains a security flaw in versions prior to 4.10.1, which allows unauthorized users to access sensitive data through the /wp-json/yith/wishlist/v1/lists endpoint due to inadequate permission checks. This vulnerability also enables attackers to delete wishlist items without proper authorization by exploiting a weakness in the AJAX delete_item handler's verification process. As a result, unauthenticated individuals can potentially manipulate shared wishlist pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.