TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection

2025-12-12 19:15
pimschaaf

Strategic Overview

Status
Patched in 2.11.0
Affected Version<= 2.10.0
CVSS5.3Medium
CVECVE-2025-9207
View all TI WooCommerce Wishlist vulnerabilities

Vulnerability Overview

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject arbitrary HTML into wishlist items.

Technical Analysis

REMEDIATION: Update to version 2.11.0, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C