WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] <= 5.0.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8.
- Affected:
- up to 5.0.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2026
CVE-2026-32407 on NVD →
WPC Smart Wishlist for WooCommerce <= 5.0.8 - Missing Authorization
medium
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Feb 22, 2026
CVE-2026-32407 on NVD →
WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 5.0.5
unknown
[en] The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.5
- Disclosed:
- Oct 18, 2025
CVE-2025-11742 on NVD →
WPC Smart Wishlist for WooCommerce <= 5.0.4 - Missing Authorization to Authenticated (Subscriber+) Information Exposure
medium
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to v...
- CVSS:
- 4.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Oct 17, 2025
CVE-2025-11742 on NVD →
WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 5.0.4
unknown
[en] The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unau...
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- Oct 11, 2025
CVE-2025-11518 on NVD →
WPC Smart Wishlist for WooCommerce <= 5.0.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation
medium
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unauthent...
- CVSS:
- 5.3
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.4
- Disclosed:
- Oct 10, 2025
CVE-2025-11518 on NVD →
WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 4.7.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.2
- Disclosed:
- Nov 9, 2023
CVE-2023-34386 on NVD →
WPC Smart Wishlist for WooCommerce <= 4.7.1 - Cross-Site Request Forgery via wishlist_add and wishlist_remove
medium
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.1. This is due to missing or incorrect nonce validation on the wishlist_add and wishlist_remove functions. This makes it possible for unauthenticated attackers to add or remove w...
- CVSS:
- 4.3
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Jun 3, 2023
CVE-2023-34386 on NVD →
WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 2.9.9
unknown
[en] The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
- Affected:
- up to 2.9.9
- Fixed in:
- 2.9.9
- Disclosed:
- May 16, 2022
CVE-2022-1465 on NVD →
WPC Smart Wishlist for WooCommerce <= 2.9.8 - Reflected Cross-Site Scripting
medium
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
- CVSS:
- 6.1
- Affected:
- up to 2.9.9
- Fixed in:
- 2.9.9
- Disclosed:
- Apr 25, 2022
CVE-2022-1465 on NVD →
WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 2.9.4
unknown
[en] The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting
- Affected:
- up to 2.9.4
- Fixed in:
- 2.9.4
- Disclosed:
- Mar 28, 2022
CVE-2022-0397 on NVD →
WPC Smart Wishlist for WooCommerce <= 2.9.3 - Reflected Cross-Site Scripting
medium
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 2.9.4
- Fixed in:
- 2.9.4
- Disclosed:
- Mar 1, 2022
CVE-2022-0397 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database