PLUGIN SECURITY
Is Yith Woocommerce Wishlist safe?
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 11.0.x compatible.
What this plugin does
- Slug:
yith-woocommerce-wishlist - Author: YITHEMES
- 400000+ active installs
- 78/100 rating (262 reviews on wordpress.org)
- 31810686 all-time downloads
- On WordPress.org since 2013-05-29
wishlist for woocommercewoocommerce add to wishlistwoocommerce wishlistyith wishlistYITH WooCommerce Wishlist
Maintenance status
- Latest known version: 4.17.0
- Last updated: 2026-07-21 1:35pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 8.0+
Known vulnerabilities
8 known CVEs on file for Yith Woocommerce Wishlist.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-27329 | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 4.13.0 | 4.13.0 | 2026-05-07 | ✓ fixed in latest |
| CVE-2025-12777 | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.10.1 | Improper Authorization | Medium 5.3 | < 4.10.1 | 4.10.1 | 2025-11-18 | ✓ fixed in latest |
| CVE-2025-12427 | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] <= 4.10.0 (unfixed) | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 4.10.0 | 4.10.0 | 2025-11-18 | ✓ fixed in latest |
| CVE-2024-34385 | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.33.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 3.33.0 | 3.33.0 | 2024-05-30 | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.15.0 | — | Unknown | < 3.15.0 | 3.15.0 | 2022-11-11 | ✓ fixed in latest |
| CVE-2022-44630 | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.15.0 | Cross-Site Request Forgery (CSRF) | Medium 4.6 | < 3.15.0 | 3.15.0 | 2022-11-11 | ✓ fixed in latest |
| CVE-2019-16251 | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.14 | — | Medium 4.3 | < 2.2.14 | 2.2.14 | 2019-10-31 | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.0 | — | Unknown | < 2.2.0 | 2.2.0 | 2018-01-17 | ✓ fixed in latest |
+ 9 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.0 | — | Unknown | < 2.2.0 | 2.2.0 | 2018-01-16 | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.6.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 4.6.0 | 4.6.0 | 0000-00-00 | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0 | — | Unknown | < 4.13.0 | 4.13.0 | 0000-00-00 | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.0 | — | Unknown | < 2.2.0 | 2.2.0 | — | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.15.0 | — | Unknown | < 3.15.0 | 3.15.0 | — | ✓ fixed in latest |
| — | YITH WooCommerce Wishlist < 2.2.0 - Authenticated SQL Injection | — | Unknown | < 2.2.0 | 2.2.0 | — | ✓ fixed in latest |
| CVE-2025-5238 | YITH WooCommerce Wishlist < 4.6.0 - Contributor+ Stored XSS via id Parameter | — | Unknown | < 4.6.0 | 4.6.0 | — | ✓ fixed in latest |
| CVE-2025-12427 | YITH WooCommerce Wishlist < 4.10.1 - Unauthenticated Wishlist Rename via IDOR | — | Unknown | < 4.10.1 | 4.10.1 | — | ✓ fixed in latest |
| CVE-2026-4432 | YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR | — | Unknown | < 4.13.0 | 4.13.0 | — | ✓ fixed in latest |
How to fix it
Keep Yith Woocommerce Wishlist updated — 4.17.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.