TI WooCommerce Wishlist
cpe:2.3:a:templateinvaders:ti_woocommerce_wishlist:*:*:*:*:wordpress:*:*
- <= 2.10.0
A vulnerability allowing HTML injection has been identified in the TI WooCommerce Wishlist plugin for WordPress, affecting all versions through 2.10.0. The issue arises because the plugin accepts hidden fields without proper validation, allowing unauthenticated attackers to inject arbitrary HTML into wishlist items.
Exploitation of this vulnerability allows for HTML injection, which could be used to manipulate the appearance of the website or potentially execute malicious scripts, depending on the context in which the injected HTML is rendered.
Users are advised to update the TI WooCommerce Wishlist plugin to version 2.11.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.