Extension WordPress

Vulnérabilités WPC Smart Wishlist for WooCommerce

Cette page rassemble les failles publiées pour WPC Smart Wishlist for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
6,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPC Smart Wishlist for WooCommerce

6 fiches

CVE-2025-11742 Moyenne · 4,3
WPC Smart Wishlist for WooCommerce

WPC Smart Wishlist for WooCommerce <= 5.0.4 – Missing Authorization to Authenticated (Subscriber+) Information Exposure

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it…

Versions affectées

*-5.0.4

Correctif

5.0.5

Publication

17/10/2025

CVE-2025-11518 Moyenne · 5,3
WPC Smart Wishlist for WooCommerce

WPC Smart Wishlist for WooCommerce <= 5.0.3 – Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key…

Versions affectées

*-5.0.3

Correctif

5.0.4

Publication

10/10/2025

CVE-2023-34386 Moyenne · 4,3
WPC Smart Wishlist for WooCommerce

WPC Smart Wishlist for WooCommerce <= 4.7.1 – Cross-Site Request Forgery via wishlist_add and wishlist_remove

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.1. This is due to missing or incorrect nonce validation on the wishlist_add and wishlist_remove functions. This…

Versions affectées

*-4.7.1

Correctif

4.7.2

Publication

03/06/2023

CVE-2022-0397 Moyenne · 6,1
WPC Smart Wishlist for WooCommerce

WPC Smart Wishlist for WooCommerce <= 2.9.3 – Reflected Cross-Site Scripting

The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site…

Versions affectées

[*, 2.9.4)

Correctif

2.9.4

Publication

01/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités