
YITH WooCommerce Product Bundles Security & Risk Analysis
wordpress.org/plugins/yith-woocommerce-product-bundlesYITH WooCommerce Product Bundles allows you to bundle WooCommerce products and sell them with a unique price.
Is YITH WooCommerce Product Bundles Safe to Use in 2026?
Generally Safe
Score 99/100YITH WooCommerce Product Bundles has a strong security track record. Known vulnerabilities have been patched promptly.
The YITH WooCommerce Product Bundles plugin (v2.23.0) demonstrates several positive security practices, including the exclusive use of prepared statements for all SQL queries and a high percentage of properly escaped output, indicating a general commitment to secure coding. The presence of numerous nonce and capability checks further reinforces its defense mechanisms. However, the analysis also highlights significant concerns regarding its attack surface. With 9 AJAX handlers, 4 of which lack authentication checks, there is a clear potential for unauthorized actions to be performed by unauthenticated users. While the taint analysis did not reveal critical or high-severity flows with unsanitized paths, the single flow with an unsanitized path is a noteworthy risk, especially when coupled with the unprotected AJAX endpoints. The plugin's vulnerability history shows one previous high-severity vulnerability, specifically related to missing authorization. This pattern suggests that authorization enforcement is an area that requires continued vigilance and careful review, as it has been a point of weakness in the past. Overall, while the plugin implements good fundamental security measures, the unprotected AJAX endpoints and the history of authorization issues present the most significant risks.
Key Concerns
- 4 unprotected AJAX handlers
- 1 flow with unsanitized path
- 1 historical high-severity CVE (Missing Authorization)
YITH WooCommerce Product Bundles Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
YITH WooCommerce Product Bundles Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
YITH WooCommerce Product Bundles Attack Surface
AJAX Handlers 9
WordPress Hooks 148
Maintenance & Trust
YITH WooCommerce Product Bundles Maintenance & Trust
Maintenance Signals
Community Trust
YITH WooCommerce Product Bundles Alternatives
Product Bundle Builder for WooCommerce
easy-product-bundles-for-woocommerce
WooCommerce Product Bundle help to creates Product Bundles, Composite Products, Mix and Match, BOGO deals, Offer gift products, and Assembled Products …
WowRevenue – Product Bundles & Bulk Discounts
revenue
WowRevenue is a combination of product bundles and discount campaigns, including bulk discounts, buy x get y discounts, and more.
Forge12 Accessories for WooCommerce
f12-wc-accessories
Add optional accessories to WooCommerce products and categories. Increase your average order value with product accessories, cart crossselling and cat …
Bundle Product Manager
bundle-product-manager-for-woocommerce
Our WordPress WooCommerce plugin provides unique functionality by allowing you to easily add multiple additional products to your main product before …
Product Quick View for WooCommerce
hmh-woocommerce-quick-view
Products Quick View for WooCommerce gives your customers a true supermarket shopping experience. In a supermarket shoppers browse products on the shel …
YITH WooCommerce Product Bundles Developer Profile
33 plugins · 1.1M total installs
How We Detect YITH WooCommerce Product Bundles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yith-woocommerce-product-bundles/assets/css/yith-wcpb-admin.css/wp-content/plugins/yith-woocommerce-product-bundles/assets/css/yith-wcpb-frontend.css/wp-content/plugins/yith-woocommerce-product-bundles/assets/js/yith-wcpb-admin.js/wp-content/plugins/yith-woocommerce-product-bundles/assets/js/yith-wcpb-frontend.js/wp-content/plugins/yith-woocommerce-product-bundles/dist/css/yith-wcpb-admin.css/wp-content/plugins/yith-woocommerce-product-bundles/dist/css/yith-wcpb-frontend.css/wp-content/plugins/yith-woocommerce-product-bundles/dist/js/yith-wcpb-admin.js/wp-content/plugins/yith-woocommerce-product-bundles/dist/js/yith-wcpb-frontend.js/wp-content/plugins/yith-woocommerce-product-bundles/assets/js/yith-wcpb-admin.js/wp-content/plugins/yith-woocommerce-product-bundles/assets/js/yith-wcpb-frontend.js/wp-content/plugins/yith-woocommerce-product-bundles/dist/js/yith-wcpb-admin.js/wp-content/plugins/yith-woocommerce-product-bundles/dist/js/yith-wcpb-frontend.jsyith-woocommerce-product-bundles/assets/css/yith-wcpb-admin.css?ver=yith-woocommerce-product-bundles/assets/css/yith-wcpb-frontend.css?ver=yith-woocommerce-product-bundles/assets/js/yith-wcpb-admin.js?ver=yith-woocommerce-product-bundles/assets/js/yith-wcpb-frontend.js?ver=yith-woocommerce-product-bundles/dist/css/yith-wcpb-admin.css?ver=yith-woocommerce-product-bundles/dist/css/yith-wcpb-frontend.css?ver=yith-woocommerce-product-bundles/dist/js/yith-wcpb-admin.js?ver=yith-woocommerce-product-bundles/dist/js/yith-wcpb-frontend.js?ver=HTML / DOM Fingerprints
yith-wcpb-bundle-optionsyith-wcpb-bundle-sectionyith-wcpb-bundled-item<!-- yith_wcpb_select_product_box --><!-- yith_wcpb_select_product_box_filtered --><!-- yith_wcpb_add_product_in_bundle --><!-- yith_wcpb_admin_bundled_item_options -->data-bundle-iddata-product-idyith_wcpb_select_product_boxYITH_WCPB_ADMIN/wp-json/yith-wcpb/v1/products/wp-json/yith-wcpb/v1/bundles[yith_product_bundle][yith_bundle_item]