VYPR

YITH WooCommerce Wishlist

by Yithemes

CVEs (2)

  • CVE-2026-27329MedMay 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0.

  • CVE-2019-16251MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.