TI WooCommerce Wishlist [ti-woocommerce-wishlist] <= 2.10.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0.
- Affected:
- up to 2.10.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-67929 on NVD →
TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection
medium
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 5.3
- Affected:
- up to 2.10.0
- Fixed in:
- 2.11.0
- Disclosed:
- Dec 12, 2025
CVE-2025-9207 on NVD →
TI WooCommerce Wishlist <= 2.10.0 - Missing Authorization
medium
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.10.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.10.0
- Fixed in:
- 2.11.0
- Disclosed:
- Nov 21, 2025
CVE-2025-67929 on NVD →
TI WooCommerce Wishlist <= 2.10.0 - Missing Authorization
medium
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.10.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 6.5
- Affected:
- up to 2.10.0
- Fixed in:
- 2.11.0
- Disclosed:
- Sep 22, 2025
CVE-2025-58247 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] <= 2.9.2 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a before 2.10.0.
- Affected:
- up to 2.9.2
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-47577 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] <= 2.9.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.10.0.
- Affected:
- up to 2.9.2
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-32920 on NVD →
TI WooCommerce Wishlist <= 2.9.2 - Unauthenticated Arbitrary File Upload
critical
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the tinvwl_upload_file_wc_fields_factory() function which has 'test_type' for 'wp_handle_upload' set to false in all versions up to, and including, 2.9.2. This makes it possible for unauthenti...
- CVSS:
- 9.8
- Affected:
- up to 2.9.2
- Fixed in:
- 2.10.0
- Disclosed:
- May 16, 2025
CVE-2025-47577 on NVD →
TI WooCommerce Wishlist <= 2.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 2.10.0
- Fixed in:
- 2.11.0
- Disclosed:
- May 15, 2025
CVE-2025-32920 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.2
unknown
[en] The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform l...
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Dec 4, 2024
CVE-2024-10567 on NVD →
TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access
high
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limite...
- CVSS:
- 7.5
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Dec 3, 2024
CVE-2024-10567 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.1
unknown
[en] The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already exi...
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Oct 10, 2024
CVE-2024-9156 on NVD →
TI WooCommerce Wishlist <= 2.9.0 - Unauthenticated SQL Injection via 'lang'
high
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'lang' parameter in all versions up to, and including, 2.9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- CVSS:
- 7.5
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.1
- Disclosed:
- Sep 19, 2024
CVE-2024-9156 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Aug 29, 2024
CVE-2024-43917 on NVD →
TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection
critical
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional...
- CVSS:
- 9.8
- Affected:
- up to 2.8.2
- Fixed in:
- 2.9.0
- Disclosed:
- Aug 22, 2024
CVE-2024-43917 on NVD →
TI WooCommerce Wishlist <= 2.7.3 - Unauthenticated Blind SQL Injection via Rest API
critical
The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versions up to, and including, 2.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...
- CVSS:
- 9.8
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 31, 2023
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4
unknown
The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versions up to, and including, 2.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 31, 2023
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.7.4
unknown
Update the WordPress TI WooCommerce Wishlist plugin to the latest available version (at least 2.7.4).
WordFence discovered and reported this SQL Injection vulnerability in WordPress TI WooCommerce Wishlist Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to s...
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Jul 31, 2023
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.6.2
- Fixed in:
- 1.7.0
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12
unknown
[en] The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain other...
- Affected:
- up to 1.21.12
- Fixed in:
- 1.21.12
- Disclosed:
- Jun 7, 2023
CVE-2020-36725 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.40.1
unknown
[en] The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attac...
- Affected:
- up to 1.40.1
- Fixed in:
- 1.40.1
- Disclosed:
- Feb 28, 2022
CVE-2022-0412 on NVD →
TI WooCommerce Wishlist / TI WooCommerce Wishlist Pro < 1.40.1 - Unauthenticated SQL Injection
critical
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
- CVSS:
- 9.8
- Affected:
- up to 1.40.1
- Fixed in:
- 1.40.1
- Disclosed:
- Jan 31, 2022
CVE-2022-0412 on NVD →
TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 - Arbitrary Options Update
high
The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise...
- CVSS:
- 8.8
- Affected:
- up to 1.21.11
- Fixed in:
- 1.21.12
- Disclosed:
- Oct 16, 2020
CVE-2020-36725 on NVD →
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12
unknown
The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise...
- Affected:
- up to 1.21.12
- Fixed in:
- 1.21.12
- Disclosed:
- Oct 16, 2020
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12
unknown
Authenticated WP Options Change vulnerability found by Jerome Bruandet (NinTechNet) in WordPress TI WooCommerce Wishlist plugin (versions <= 1.21.11).
- Affected:
- up to 1.21.12
- Fixed in:
- 1.21.12
- Disclosed:
- Oct 16, 2020
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.21.12
unknown
The TI WooCommerce Wishlist WordPress plugins (free and Pro) were found to be affected by an Authenticated WP Options Change security vulnerability. The vulnerability could allow an authenticated attacker to compromise a WordPress website it was installed on and its database.
- Affected:
- up to 1.21.12
- Fixed in:
- 1.21.12
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 1.7.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database