plugin

Smart Wishlist For More Convert Premium Vulnerabilities

1 known security issue reported for the Smart Wishlist For More Convert Premium WordPress plugin. Most recent disclosed May 4, 2026.

1 critical

Running Smart Wishlist For More Convert Premium on your site? Check whether your installed version is affected.

Scan your site free

MoreConvert Pro <= 1.9.14 - Authentication Bypass via Waitlist Guest Verification Token Reuse

critical

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated at...

CVSS:
9.8
Affected:
up to 1.9.14
Fixed in:
1.9.15
Disclosed:
May 4, 2026

CVE-2026-5722 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database