YITH WooCommerce Popup
YITH WooCommerce Popup has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 7.1 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Missing Authorization.
Every one of the 3 issues recorded for YITH WooCommerce Popup has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. YITH WooCommerce Popup is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
Read the full analysisVulnerability Records

YITH WooCommerce Popup
Author
YITHEMES
woocommercePopups are a powerful tool to catch your users’ attention: direct and customizable, with YITH WooCommerce Popup you will be able to use them in the best way to accomplish your achievements. Add them in every page you want, using a template you can customize freely: create the best popup window for your needs, and add a message, a newsletter form or the products of your own shop. Plugin’s features: Popup settings section Creation of endless popups Freedom to assign one different popup for each page Add a form for newsletter Modify graphically the popup style Add products from the store Suggestions If you have any suggestions concerning how to improve YITH WooCommerce Popup, you can write to us, so that we can improve YITH WooCommerce Popup.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C