Extension WordPress
Vulnérabilités TI WooCommerce Wishlist
Cette page rassemble les failles publiées pour TI WooCommerce Wishlist, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de TI WooCommerce Wishlist
12 fiches
TI WooCommerce Wishlist <= 2.10.0 – Unauthenticated HTML Injection
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can…
*-2.10.0
2.11.0
12/12/2025
TI WooCommerce Wishlist <= 2.10.0 – Missing Authorization
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.10.0. This makes it possible for unauthenticated attackers to perform…
*-2.10.0
2.11.0
21/11/2025
TI WooCommerce Wishlist <= 2.10.0 – Missing Authorization
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.10.0. This makes it possible for unauthenticated attackers to perform an…
*-2.10.0
2.11.0
22/09/2025
TI WooCommerce Wishlist <= 2.9.2 – Unauthenticated Arbitrary File Upload
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the tinvwl_upload_file_wc_fields_factory() function which has 'test_type' for 'wp_handle_upload' set to false in all versions up to, and including,…
*-2.9.2
2.10.0
16/05/2025
TI WooCommerce Wishlist <= 2.10.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-2.10.0
2.11.0
15/05/2025
TI WooCommerce Wishlist <= 2.9.1 – Missing Authorization to Unauthenticated Plugin Setup Wizard Access
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated…
*-2.9.1
2.9.2
03/12/2024
TI WooCommerce Wishlist <= 2.9.0 – Unauthenticated SQL Injection via 'lang'
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'lang' parameter in all versions up to, and including, 2.9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-2.9.0
2.9.1
19/09/2024
TI WooCommerce Wishlist <= 2.8.2 – Unauthenticated SQL Injection
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-2.8.2
2.9.0
22/08/2024
TI WooCommerce Wishlist <= 2.7.3 – Unauthenticated Blind SQL Injection via Rest API
The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versions up to, and including, 2.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
[*, 2.7.4)
2.7.4
31/07/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.6.2
1.7.0
18/07/2023
TI WooCommerce Wishlist / TI WooCommerce Wishlist Pro < 1.40.1 – Unauthenticated SQL Injection
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated…
[*, 1.40.1)
1.40.1
31/01/2022
TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 – Arbitrary Options Update
The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated…
*-1.21.11
1.21.12
16/10/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.