PLUGIN SECURITY
Is TI WooCommerce Wishlist safe?
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
What this plugin does
- Slug:
ti-woocommerce-wishlist - Author: templateinvaders
- 100000+ active installs
- 94/100 rating (499 reviews on wordpress.org)
- 6302022 all-time downloads
- On WordPress.org since 2016-09-22
ecommerceshopWishlistwoocommercewoocommerce wishlist
Maintenance status
- Last updated: 2026-06-24 7:58pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
11 known CVEs on file for TI WooCommerce Wishlist.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-67929 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 | Missing Authorization | Medium 5.3 | < 2.11.0 | 2.11.0 | 2025-11-21 | — |
| CVE-2025-47577 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.10.0 | Unrestricted Upload of File with Dangerous Type | Critical 10.0 | < 2.10.0 | 2.10.0 | 2025-05-16 | — |
| CVE-2025-32920 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.11.0 | 2.11.0 | 2025-05-15 | — |
| CVE-2024-10567 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.2 | Missing Authorization | High 7.5 | < 2.9.2 | 2.9.2 | 2024-12-03 | — |
| CVE-2024-9156 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 2.9.1 | 2.9.1 | 2024-09-19 | — |
| CVE-2024-43917 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 2.9.0 | 2.9.0 | 2024-08-22 | — |
| — | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4 | — | Unknown | < 2.7.4 | 2.7.4 | 2023-07-31 | — |
| — | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4 | — | Unknown | < 2.7.4 | 2.7.4 | 2023-07-31 | — |
+ 10 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-33999 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.7.0 | 1.7.0 | 2023-07-18 | — |
| CVE-2022-0412 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.40.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 1.40.1 | 1.40.1 | 2022-01-31 | — |
| — | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12 | — | Unknown | < 1.21.12 | 1.21.12 | 2020-10-16 | — |
| CVE-2020-36725 | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12 | Missing Authorization | High 8.8 | < 1.21.12 | 1.21.12 | 2020-10-16 | — |
| — | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 | — | Medium 5.3 | < 2.11.0 | 2.11.0 | 0000-00-00 | — |
| — | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 | — | Medium 5.3 | < 2.11.0 | 2.11.0 | 0000-00-00 | — |
| — | TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12 | — | Unknown | < 1.21.12 | 1.21.12 | — | — |
| CVE-2020-36725 | TI WooCommerce Wishlist - Authenticated WP Options Change | — | Unknown | < 1.21.12 | 1.21.12 | — | — |
| CVE-2025-58247 | TI WooCommerce Wishlist < 2.11.0 - Missing Authorization | — | Unknown | < 2.11.0 | 2.11.0 | — | — |
| CVE-2025-9207 | TI WooCommerce Wishlist < 2.11.0 - Unauthenticated HTML Injection | — | Unknown | < 2.11.0 | 2.11.0 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooCommerce — 7000000+ active installs — 90/100 (4820)
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation — 1000000+ active installs — 86/100 (815) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
- WPML Multilingual & Multicurrency for WooCommerce — 100000+ active installs — 84/100 (453)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.