PLUGIN SECURITY

Is Yith Woocommerce Wishlist safe?

YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 11.0.x compatible.

What this plugin does

  • Slug: yith-woocommerce-wishlist
  • Author: YITHEMES
  • 400000+ active installs
  • 78/100 rating (262 reviews on wordpress.org)
  • 31810686 all-time downloads
  • On WordPress.org since 2013-05-29

wishlist for woocommercewoocommerce add to wishlistwoocommerce wishlistyith wishlistYITH WooCommerce Wishlist

Maintenance status

  • Latest known version: 4.17.0
  • Last updated: 2026-07-21 1:35pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 8.0+

Known vulnerabilities

8 known CVEs on file for Yith Woocommerce Wishlist.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-27329 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0 Authorization Bypass Through User-Controlled Key Medium 5.3 < 4.13.0 4.13.0 2026-05-07 ✓ fixed in latest
CVE-2025-12777 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.10.1 Improper Authorization Medium 5.3 < 4.10.1 4.10.1 2025-11-18 ✓ fixed in latest
CVE-2025-12427 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] <= 4.10.0 (unfixed) Authorization Bypass Through User-Controlled Key Medium 5.3 < 4.10.0 4.10.0 2025-11-18 ✓ fixed in latest
CVE-2024-34385 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.33.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.33.0 3.33.0 2024-05-30 ✓ fixed in latest
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.15.0 Unknown < 3.15.0 3.15.0 2022-11-11 ✓ fixed in latest
CVE-2022-44630 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.15.0 Cross-Site Request Forgery (CSRF) Medium 4.6 < 3.15.0 3.15.0 2022-11-11 ✓ fixed in latest
CVE-2019-16251 YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.14 Medium 4.3 < 2.2.14 2.2.14 2019-10-31 ✓ fixed in latest
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.0 Unknown < 2.2.0 2.2.0 2018-01-17 ✓ fixed in latest
+ 9 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.0 Unknown < 2.2.0 2.2.0 2018-01-16 ✓ fixed in latest
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.6.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.6.0 4.6.0 0000-00-00 ✓ fixed in latest
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0 Unknown < 4.13.0 4.13.0 0000-00-00 ✓ fixed in latest
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 2.2.0 Unknown < 2.2.0 2.2.0 ✓ fixed in latest
YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 3.15.0 Unknown < 3.15.0 3.15.0 ✓ fixed in latest
YITH WooCommerce Wishlist < 2.2.0 - Authenticated SQL Injection Unknown < 2.2.0 2.2.0 ✓ fixed in latest
CVE-2025-5238 YITH WooCommerce Wishlist < 4.6.0 - Contributor+ Stored XSS via id Parameter Unknown < 4.6.0 4.6.0 ✓ fixed in latest
CVE-2025-12427 YITH WooCommerce Wishlist < 4.10.1 - Unauthenticated Wishlist Rename via IDOR Unknown < 4.10.1 4.10.1 ✓ fixed in latest
CVE-2026-4432 YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR Unknown < 4.13.0 4.13.0 ✓ fixed in latest

How to fix it

Keep Yith Woocommerce Wishlist updated — 4.17.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.