TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection
2025-12-12 19:15
pimschaafStrategic Overview
StatusPatched in 2.11.0
Affected PluginTI WooCommerce Wishlist
Affected Version
<= 2.10.0CVSS5.3Medium
CVE
CVE-2025-9207Vulnerability Overview
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject arbitrary HTML into wishlist items.
Technical Analysis
REMEDIATION: Update to version 2.11.0, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C