PLUGIN SECURITY

Is TI WooCommerce Wishlist safe?

Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!

What this plugin does

  • Slug: ti-woocommerce-wishlist
  • Author: templateinvaders
  • 100000+ active installs
  • 94/100 rating (499 reviews on wordpress.org)
  • 6302022 all-time downloads
  • On WordPress.org since 2016-09-22

ecommerceshopWishlistwoocommercewoocommerce wishlist

Maintenance status

  • Last updated: 2026-06-24 7:58pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

11 known CVEs on file for TI WooCommerce Wishlist.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-67929 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 Missing Authorization Medium 5.3 < 2.11.0 2.11.0 2025-11-21
CVE-2025-47577 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.10.0 Unrestricted Upload of File with Dangerous Type Critical 10.0 < 2.10.0 2.10.0 2025-05-16
CVE-2025-32920 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.11.0 2.11.0 2025-05-15
CVE-2024-10567 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.2 Missing Authorization High 7.5 < 2.9.2 2.9.2 2024-12-03
CVE-2024-9156 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 2.9.1 2.9.1 2024-09-19
CVE-2024-43917 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 2.9.0 2.9.0 2024-08-22
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4 Unknown < 2.7.4 2.7.4 2023-07-31
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4 Unknown < 2.7.4 2.7.4 2023-07-31
+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-33999 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.7.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 1.7.0 1.7.0 2023-07-18
CVE-2022-0412 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.40.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 1.40.1 1.40.1 2022-01-31
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12 Unknown < 1.21.12 1.21.12 2020-10-16
CVE-2020-36725 TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12 Missing Authorization High 8.8 < 1.21.12 1.21.12 2020-10-16
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 Medium 5.3 < 2.11.0 2.11.0 0000-00-00
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.11.0 Medium 5.3 < 2.11.0 2.11.0 0000-00-00
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12 Unknown < 1.21.12 1.21.12
CVE-2020-36725 TI WooCommerce Wishlist - Authenticated WP Options Change Unknown < 1.21.12 1.21.12
CVE-2025-58247 TI WooCommerce Wishlist < 2.11.0 - Missing Authorization Unknown < 2.11.0 2.11.0
CVE-2025-9207 TI WooCommerce Wishlist < 2.11.0 - Unauthenticated HTML Injection Unknown < 2.11.0 2.11.0

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.