Extension WordPress

Vulnérabilités TI WooCommerce Wishlist

Cette page rassemble les failles publiées pour TI WooCommerce Wishlist, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
4Critiques
12Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de TI WooCommerce Wishlist

12 fiches

CVE-2025-47577 Critique · 9,8
TI WooCommerce Wishlist

TI WooCommerce Wishlist <= 2.9.2 – Unauthenticated Arbitrary File Upload

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the tinvwl_upload_file_wc_fields_factory() function which has 'test_type' for 'wp_handle_upload' set to false in all versions up to, and including,…

Versions affectées

*-2.9.2

Correctif

2.10.0

Publication

16/05/2025

CVE-2025-32920 Moyenne · 6,4
TI WooCommerce Wishlist

TI WooCommerce Wishlist <= 2.10.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.10.0

Correctif

2.11.0

Publication

15/05/2025

CVE-2024-10567 Élevée · 7,5
TI WooCommerce Wishlist

TI WooCommerce Wishlist <= 2.9.1 – Missing Authorization to Unauthenticated Plugin Setup Wizard Access

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated…

Versions affectées

*-2.9.1

Correctif

2.9.2

Publication

03/12/2024

CVE-2023-33999 Moyenne · 6,1
TI WooCommerce Wishlist

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.6.2

Correctif

1.7.0

Publication

18/07/2023

CVE-2022-0412 Critique · 9,8
TI WooCommerce Wishlist

TI WooCommerce Wishlist / TI WooCommerce Wishlist Pro < 1.40.1 – Unauthenticated SQL Injection

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated…

Versions affectées

[*, 1.40.1)

Correctif

1.40.1

Publication

31/01/2022

CVE-2020-36725 Élevée · 8,8
TI WooCommerce Wishlist

TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 – Arbitrary Options Update

The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated…

Versions affectées

*-1.21.11

Correctif

1.21.12

Publication

16/10/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités