cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwish-list-for-woocommerce wish-list-for-woocommerce

Direction: descending
Jul 18, 2025

Wishlist for WooCommerce: Multi Wishlists Per Customer # CVE-2025-49319

CVE, Research URL

CVE-2025-49319

Date
Jul 16, 2025
Research Description
Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wishlist for WooCommerce: from n/a through 3.2.3.
Affected versions
Min -, max -.
Status
vulnerable
May 27, 2025

Wishlist for WooCommerce: Multi Wishlists Per Customer # CVE-2025-48237

CVE, Research URL

CVE-2025-48237

Date
May 19, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce allows Stored XSS. This issue affects Wishlist for WooCommerce: from n/a through 3.2.2.
Affected versions
Min -, max -.
Status
vulnerable
Mar 08, 2025

Wishlist for WooCommerce: Multi Wishlists Per Customer # CVE-2024-13774

CVE, Research URL

CVE-2024-13774

Date
Mar 08, 2025
Research Description
The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. This is due to missing or incorrect nonce validation on the 'save_to_multiple_wishlist' function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Dec 23, 2024

Wishlist for WooCommerce: Multi Wishlists Per Customer # CVE-2024-56228

CVE, Research URL

CVE-2024-56228

Date
Dec 31, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce: Multi Wishlists Per Customer allows Reflected XSS.This issue affects Wishlist for WooCommerce: Multi Wishlists Per Customer: from n/a through 3.1.2.
Affected versions
Min -, max -.
Status
vulnerable
Nov 24, 2024

Wishlist for WooCommerce: Multi Wishlists Per Customer # CVE-2024-10519

CVE, Research URL

CVE-2024-10519

Date
Nov 23, 2024
Research Description
The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Note: Only WordPress installations with versions of PHP <=7.4 are affected by this vulnerability.
Affected versions
Min -, max -.
Status
vulnerable