plugin

Woo Smart Wishlist Vulnerabilities

12 known security issues reported for the Woo Smart Wishlist WordPress plugin. Most recent disclosed Mar 13, 2026.

6 medium

Running Woo Smart Wishlist on your site? Check whether your installed version is affected.

Scan your site free

WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] <= 5.0.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8.

Affected:
up to 5.0.8
Fix:
No patched version reported
Disclosed:
Mar 13, 2026

CVE-2026-32407 on NVD →

WPC Smart Wishlist for WooCommerce <= 5.0.8 - Missing Authorization

medium

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.0.8
Fixed in:
5.0.9
Disclosed:
Feb 22, 2026

CVE-2026-32407 on NVD →

WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 5.0.5

unknown

[en] The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

Affected:
up to 5.0.5
Fixed in:
5.0.5
Disclosed:
Oct 18, 2025

CVE-2025-11742 on NVD →

WPC Smart Wishlist for WooCommerce <= 5.0.4 - Missing Authorization to Authenticated (Subscriber+) Information Exposure

medium

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to v...

CVSS:
4.3
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Oct 17, 2025

CVE-2025-11742 on NVD →

WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 5.0.4

unknown

[en] The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unau...

Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Oct 11, 2025

CVE-2025-11518 on NVD →

WPC Smart Wishlist for WooCommerce <= 5.0.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

medium

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for unauthent...

CVSS:
5.3
Affected:
up to 5.0.3
Fixed in:
5.0.4
Disclosed:
Oct 10, 2025

CVE-2025-11518 on NVD →

WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 4.7.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.

Affected:
up to 4.7.2
Fixed in:
4.7.2
Disclosed:
Nov 9, 2023

CVE-2023-34386 on NVD →

WPC Smart Wishlist for WooCommerce <= 4.7.1 - Cross-Site Request Forgery via wishlist_add and wishlist_remove

medium

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.1. This is due to missing or incorrect nonce validation on the wishlist_add and wishlist_remove functions. This makes it possible for unauthenticated attackers to add or remove w...

CVSS:
4.3
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Jun 3, 2023

CVE-2023-34386 on NVD →

WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 2.9.9

unknown

[en] The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

Affected:
up to 2.9.9
Fixed in:
2.9.9
Disclosed:
May 16, 2022

CVE-2022-1465 on NVD →

WPC Smart Wishlist for WooCommerce <= 2.9.8 - Reflected Cross-Site Scripting

medium

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.

CVSS:
6.1
Affected:
up to 2.9.9
Fixed in:
2.9.9
Disclosed:
Apr 25, 2022

CVE-2022-1465 on NVD →

WPC Smart Wishlist for WooCommerce [woo-smart-wishlist] < 2.9.4

unknown

[en] The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Mar 28, 2022

CVE-2022-0397 on NVD →

WPC Smart Wishlist for WooCommerce <= 2.9.3 - Reflected Cross-Site Scripting

medium

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Mar 1, 2022

CVE-2022-0397 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database