All 6 CVE vulnerabilities found in Wishlist for WooCommerce, with AI-generated Chinese analysis, references, and POCs.
Vendor: WebToffee
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-69334 | WordPress Wishlist for WooCommerce plugin <= 3.3.0 - Cross Site Scripting (XSS) vulnerability CWE-79 | 6.5 | Medium | 2026-01-06 |
| CVE-2025-12040 | Wishlist for WooCommerce <= 1.1.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation CWE-639 | 6.5 | Medium | 2025-11-25 |
| CVE-2025-49319 | WordPress Wishlist for WooCommerce <= 3.2.3 - Broken Access Control Vulnerability CWE-862 | 6.5 | Medium | 2025-07-16 |
| CVE-2025-48237 | WordPress Wishlist for WooCommerce plugin <= 3.2.2 - Cross Site Scripting (XSS) Vulnerability CWE-79 | 6.5 | Medium | 2025-05-19 |
| CVE-2025-24657 | WordPress Wishlist for WooCommerce plugin <=2.1.2 - Cross Site Scripting (XSS) vulnerability CWE-79 | 5.9 | Medium | 2025-01-24 |
| CVE-2024-56228 | WordPress Wishlist for WooCommerce: Multi Wishlists Per Customer plugin <= 3.1.2 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2024-12-31 |
All 6 known CVE vulnerabilities affecting Wishlist for WooCommerce with full Chinese analysis, references, and POCs where available.