
Wishlist for WooCommerce: Multi Wishlists Per Customer Security & Risk Analysis
wordpress.org/plugins/wish-list-for-woocommerceIncrease loyalty & sales by letting customers create, manage & share multiple wishlists on your WooCommerce store.
Is Wishlist for WooCommerce: Multi Wishlists Per Customer Safe to Use in 2026?
Generally Safe
Score 95/100Wishlist for WooCommerce: Multi Wishlists Per Customer has a strong security track record. Known vulnerabilities have been patched promptly.
The "wish-list-for-woocommerce" v3.4.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no immediately exploitable entry points without authentication or permission checks, and all SQL queries are properly prepared. The absence of dangerous functions, file operations, and external HTTP requests is also a good indicator of secure coding practices in these areas. However, the taint analysis, while showing no critical or high severity issues, did identify two flows with unsanitized paths. This, coupled with the fact that 18% of output is not properly escaped, suggests potential vulnerabilities like Cross-Site Scripting (XSS) that could be exploited if an attacker can influence the data that reaches these outputs. The plugin's vulnerability history is a significant concern, with five medium-severity CVEs recorded, including common types like Missing Authorization, CSRF, and XSS. While there are currently no unpatched vulnerabilities, the recurring nature of these past issues, especially the lack of authorization and XSS flaws, indicates a pattern of potential weaknesses that could resurface. The presence of capability checks on only a small fraction of entry points is also a notable concern, as it leaves many potential interaction points less secure than they could be. Overall, while some foundational security aspects are well-handled, the identified taint flows, unescaped output, and historical vulnerability patterns necessitate caution and diligent patching.
Key Concerns
- Unsanitized paths in taint analysis
- Improperly escaped output detected
- Five medium severity CVEs in history
- Lack of capability checks on entry points
Wishlist for WooCommerce: Multi Wishlists Per Customer Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Wishlist for WooCommerce <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Wishlist for WooCommerce <= 3.2.3 - Missing Authorization
Wishlist for WooCommerce <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.7 - Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name
Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.2 - Reflected Cross-Site Scripting
Wishlist for WooCommerce: Multi Wishlists Per Customer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wishlist for WooCommerce: Multi Wishlists Per Customer Attack Surface
Shortcodes 4
WordPress Hooks 84
Maintenance & Trust
Wishlist for WooCommerce: Multi Wishlists Per Customer Maintenance & Trust
Maintenance Signals
Community Trust
Wishlist for WooCommerce: Multi Wishlists Per Customer Alternatives
QODE Wishlist for WooCommerce
qode-wishlist-for-woocommerce
Qode Wishlist for WooCommerce plugin is the ideal toolkit for letting your visitors save & share comprehensive lists with their products of interest.
Addonify – WooCommerce Wishlist
addonify-wishlist
Addonify WooCommerce Wishlist is a light-weight yet powerful tool that adds a wishlist functionality to your e-commerce shop.
Airy Wishlist for WooCommerce
airy-wishlist
A powerful and user-friendly wishlist plugin for WooCommerce. Let customers save their favorite products for later!
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
WishSuite – Wishlist for WooCommerce
wishsuite
WishSuite integrates wishlist functionality into your WooCommerce store, so customers can easily add products to their wishlists for later purchases.
Wishlist for WooCommerce: Multi Wishlists Per Customer Developer Profile
63 plugins · 136K total installs
How We Detect Wishlist for WooCommerce: Multi Wishlists Per Customer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wish-list-for-woocommerce/assets/css/frontend.css/wp-content/plugins/wish-list-for-woocommerce/assets/js/frontend.js/wp-content/plugins/wish-list-for-woocommerce/assets/css/style.css/wp-content/plugins/wish-list-for-woocommerce/assets/js/frontend.jswish-list-for-woocommerce/assets/css/frontend.css?ver=wish-list-for-woocommerce/assets/js/frontend.js?ver=wish-list-for-woocommerce/assets/css/style.css?ver=HTML / DOM Fingerprints
alg-wc-wl-wishlist-buttonalg-wc-wl-wishlist-button-wrapperalg-wc-wl-add-to-wishlistalg-wc-wl-added-to-wishlistalg-wc-wl-wishlist-counter<!--Alg_WC_Wishlist_For_Woocommerce--><!--wish-list-for-woocommerce-->data-wishlist-iddata-product-idalg_wc_wl_frontend_params