plugin

Ti Woocommerce Wishlist Vulnerabilities

26 known security issues reported for the Ti Woocommerce Wishlist WordPress plugin. Most recent disclosed Dec 16, 2025.

4 critical 3 high 5 medium

Running Ti Woocommerce Wishlist on your site? Check whether your installed version is affected.

Scan your site free

TI WooCommerce Wishlist [ti-woocommerce-wishlist] <= 2.10.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0.

Affected:
up to 2.10.0
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-67929 on NVD →

TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection

medium

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
5.3
Affected:
up to 2.10.0
Fixed in:
2.11.0
Disclosed:
Dec 12, 2025

CVE-2025-9207 on NVD →

TI WooCommerce Wishlist <= 2.10.0 - Missing Authorization

medium

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.10.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.10.0
Fixed in:
2.11.0
Disclosed:
Nov 21, 2025

CVE-2025-67929 on NVD →

TI WooCommerce Wishlist <= 2.10.0 - Missing Authorization

medium

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.10.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
6.5
Affected:
up to 2.10.0
Fixed in:
2.11.0
Disclosed:
Sep 22, 2025

CVE-2025-58247 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] <= 2.9.2 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a before 2.10.0.

Affected:
up to 2.9.2
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-47577 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] <= 2.9.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.10.0.

Affected:
up to 2.9.2
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-32920 on NVD →

TI WooCommerce Wishlist <= 2.9.2 - Unauthenticated Arbitrary File Upload

critical

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the tinvwl_upload_file_wc_fields_factory() function which has 'test_type' for 'wp_handle_upload' set to false in all versions up to, and including, 2.9.2. This makes it possible for unauthenti...

CVSS:
9.8
Affected:
up to 2.9.2
Fixed in:
2.10.0
Disclosed:
May 16, 2025

CVE-2025-47577 on NVD →

TI WooCommerce Wishlist <= 2.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.10.0
Fixed in:
2.11.0
Disclosed:
May 15, 2025

CVE-2025-32920 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.2

unknown

[en] The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform l...

Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Dec 4, 2024

CVE-2024-10567 on NVD →

TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access

high

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limite...

CVSS:
7.5
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Dec 3, 2024

CVE-2024-10567 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.1

unknown

[en] The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already exi...

Affected:
up to 2.9.1
Fixed in:
2.9.1
Disclosed:
Oct 10, 2024

CVE-2024-9156 on NVD →

TI WooCommerce Wishlist <= 2.9.0 - Unauthenticated SQL Injection via 'lang'

high

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'lang' parameter in all versions up to, and including, 2.9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

CVSS:
7.5
Affected:
up to 2.9.0
Fixed in:
2.9.1
Disclosed:
Sep 19, 2024

CVE-2024-9156 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.

Affected:
up to 2.9.0
Fixed in:
2.9.0
Disclosed:
Aug 29, 2024

CVE-2024-43917 on NVD →

TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection

critical

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional...

CVSS:
9.8
Affected:
up to 2.8.2
Fixed in:
2.9.0
Disclosed:
Aug 22, 2024

CVE-2024-43917 on NVD →

TI WooCommerce Wishlist <= 2.7.3 - Unauthenticated Blind SQL Injection via Rest API

critical

The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versions up to, and including, 2.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...

CVSS:
9.8
Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
Jul 31, 2023

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4

unknown

The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versions up to, and including, 2.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...

Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
Jul 31, 2023

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4

unknown

Update the WordPress TI WooCommerce Wishlist plugin to the latest available version (at least 2.7.4). WordFence discovered and reported this SQL Injection vulnerability in WordPress TI WooCommerce Wishlist Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to s...

Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
Jul 31, 2023

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 1.6.2
Fixed in:
1.7.0
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12

unknown

[en] The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain other...

Affected:
up to 1.21.12
Fixed in:
1.21.12
Disclosed:
Jun 7, 2023

CVE-2020-36725 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.40.1

unknown

[en] The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attac...

Affected:
up to 1.40.1
Fixed in:
1.40.1
Disclosed:
Feb 28, 2022

CVE-2022-0412 on NVD →

TI WooCommerce Wishlist / TI WooCommerce Wishlist Pro < 1.40.1 - Unauthenticated SQL Injection

critical

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

CVSS:
9.8
Affected:
up to 1.40.1
Fixed in:
1.40.1
Disclosed:
Jan 31, 2022

CVE-2022-0412 on NVD →

TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 - Arbitrary Options Update

high

The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise...

CVSS:
8.8
Affected:
up to 1.21.11
Fixed in:
1.21.12
Disclosed:
Oct 16, 2020

CVE-2020-36725 on NVD →

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12

unknown

The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise...

Affected:
up to 1.21.12
Fixed in:
1.21.12
Disclosed:
Oct 16, 2020

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12

unknown

Authenticated WP Options Change vulnerability found by Jerome Bruandet (NinTechNet) in WordPress TI WooCommerce Wishlist plugin (versions <= 1.21.11).

Affected:
up to 1.21.12
Fixed in:
1.21.12
Disclosed:
Oct 16, 2020

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12

unknown

The TI WooCommerce Wishlist WordPress plugins (free and Pro) were found to be affected by an Authenticated WP Options Change security vulnerability. The vulnerability could allow an authenticated attacker to compromise a WordPress website it was installed on and its database.

Affected:
up to 1.21.12
Fixed in:
1.21.12

TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.7.0

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.7.0
Fixed in:
1.7.0

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database