CVE · Medium

CVE-2026-27329 — YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-27329 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0 Authorization Bypass Through User-Controlled Key Medium 5.3 < 4.13.0 4.13.0 2026-05-07

CVE-2026-27329

A security flaw exists within the YITH WooCommerce Wishlist plugin for WordPress, affecting all versions prior to 4.12.1. The issue stems from inadequate verification of a user-supplied parameter, which can be exploited by malicious actors without authentication credentials. This vulnerability enables unauthorized actions to be carried out.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.