TI WooCommerce Wishlist HTML Injection Vulnerability

Vulnerability

A vulnerability allowing HTML injection has been identified in the TI WooCommerce Wishlist plugin for WordPress, affecting all versions through 2.10.0. The issue arises because the plugin accepts hidden fields without proper validation, allowing unauthenticated attackers to inject arbitrary HTML into wishlist items.

Impact

Exploitation of this vulnerability allows for HTML injection, which could be used to manipulate the appearance of the website or potentially execute malicious scripts, depending on the context in which the injected HTML is rendered.

Remediation

Users are advised to update the TI WooCommerce Wishlist plugin to version 2.11.0 or later.

Added: Dec 13, 2025, 4:24 PM
Updated: Dec 13, 2025, 4:24 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
9.0
remediation
7.7
relevance
1.4
threat
3.2
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.