cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forti-woocommerce-wishlist ti-woocommerce-wishlist

Direction: ascending
Jun 06, 2024

TI WooCommerce Wishlist # CVE-2020-36725

CVE, Research URL

CVE-2020-36725

Date
Jun 07, 2023
Research Description
The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise restricted access to the vulnerable blog and update any settings.
Affected versions
Min -, max -.
Status
vulnerable

TI WooCommerce Wishlist # CVE-2022-0412

CVE, Research URL

CVE-2022-0412

Date
Feb 28, 2022
Research Description
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
Affected versions
Min -, max -.
Status
vulnerable
Aug 25, 2024

TI WooCommerce Wishlist # CVE-2024-43917

CVE, Research URL

CVE-2024-43917

Date
Aug 29, 2024
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.
Affected versions
Min -, max -.
Status
vulnerable
Oct 11, 2024

TI WooCommerce Wishlist # CVE-2024-9156

CVE, Research URL

CVE-2024-9156

Date
Oct 10, 2024
Research Description
The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
Min -, max -.
Status
vulnerable
Dec 05, 2024

TI WooCommerce Wishlist # CVE-2024-10567

CVE, Research URL

CVE-2024-10567

Date
Dec 04, 2024
Research Description
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates.
Affected versions
Min -, max -.
Status
vulnerable
May 20, 2025

TI WooCommerce Wishlist # CVE-2025-32920

CVE, Research URL

CVE-2025-32920

Date
May 19, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.9.2.
Affected versions
Min -, max -.
Status
vulnerable

TI WooCommerce Wishlist # CVE-2025-47577

CVE, Research URL

CVE-2025-47577

Date
May 20, 2025
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through 2.9.2.
Affected versions
Min -, max -.
Status
vulnerable