
YITH WooCommerce Wishlist Security & Risk Analysis
wordpress.org/plugins/yith-woocommerce-wishlistYITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
Is YITH WooCommerce Wishlist Safe to Use in 2026?
Generally Safe
Score 92/100YITH WooCommerce Wishlist has a strong security track record. Known vulnerabilities have been patched promptly.
The YITH WooCommerce Wishlist plugin v4.13.0 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, there are notable areas of concern. The presence of one AJAX handler without authentication checks, coupled with five taint flows flagged with unsanitized paths (all of high severity), indicates potential vulnerabilities that could be exploited. The plugin's vulnerability history, including six known CVEs with a past high-severity vulnerability and common patterns of authorization and injection issues, suggests a recurring need for diligent security maintenance.
Despite a large number of entry points, the low number of unprotected ones is a positive sign. The plugin also shows robust use of nonces and capability checks. However, the identified high-severity taint flows and the history of authorization and injection-related vulnerabilities are significant risk factors. The fact that there are currently no unpatched CVEs is encouraging, but the plugin's past indicates it has been a target and has had exploitable flaws. Therefore, while the plugin has strengths, careful monitoring and timely updates are crucial to mitigate the identified risks.
Key Concerns
- AJAX handler without auth checks
- High severity taint flows with unsanitized paths
- Known high severity vulnerability in history
- Common vulnerability types: Improper Authorization
- Common vulnerability types: SQL Injection
- Bundled library (Select2) - potential for outdated version
YITH WooCommerce Wishlist Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename
YITH WooCommerce Wishlist <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
YITH WooCommerce Wishlist <= 3.32.0 - Authenticated (Admin+) Stored Cross-Site Scripting
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
YITH WooCommerce Wishlist <= 2.1.2 - SQL Injection
YITH WooCommerce Wishlist Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
YITH WooCommerce Wishlist Attack Surface
AJAX Handlers 19
Shortcodes 2
WordPress Hooks 154
Maintenance & Trust
YITH WooCommerce Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
YITH WooCommerce Wishlist Alternatives
OLLITS Wishlist for WooCommerce
ollits-woo-wishlist
Enable WooCommerce customers to effortlessly manage their personal wishlists, improving their shopping experience!
YITH Essential Kit for WooCommerce #1
yith-essential-kit-for-woocommerce-1
The YITH Essential Kit for WooCommerce #1 plugin enhance your WordPress site with this group of impressive features for WooCommerce.
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later
flexible-wishlist
Lightweight and simple WooCommerce wishlist. Increases sales. Fits any theme. Customizes texts and icons. Add to ecommerce wishlist with just 1 click.
Wishlist for WooCommerce
wt-woocommerce-wishlist
This WooCommerce wishlist plugin adds a wishlist feature to your WooCommerce store. Let the users easily add and manage products from their wishlist p …
Wishlist for WooCommerce
jvm-woocommerce-wishlist
Supercharge your sales with WooCommerce Wishlist - a powerful tool that empowers customers to create wishlists and enhances their shopping experience.
YITH WooCommerce Wishlist Developer Profile
33 plugins · 1.1M total installs
How We Detect YITH WooCommerce Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yith-woocommerce-wishlist/assets/css/yith-wcwl-main.css/wp-content/plugins/yith-woocommerce-wishlist/assets/css/yith-wcwl-general.css/wp-content/plugins/yith-woocommerce-wishlist/assets/css/yith-wcwl-responsive.css/wp-content/plugins/yith-woocommerce-wishlist/assets/css/yith-wcwl-user-panel.css/wp-content/plugins/yith-woocommerce-wishlist/assets/css/yith-wcwl-frontend.css/wp-content/plugins/yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl-functions.js/wp-content/plugins/yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl-add-to-wishlist.js/wp-content/plugins/yith-woocommerce-wishlist/assets/js/yith-wcwl-frontend.js/wp-content/plugins/yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl-functions.js/wp-content/plugins/yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl-add-to-wishlist.js/wp-content/plugins/yith-woocommerce-wishlist/assets/js/yith-wcwl-frontend.jsyith-woocommerce-wishlist/init.php?ver=yith-woocommerce-wishlist/assets/css/yith-wcwl-main.css?ver=yith-woocommerce-wishlist/assets/css/yith-wcwl-general.css?ver=yith-woocommerce-wishlist/assets/css/yith-wcwl-responsive.css?ver=yith-woocommerce-wishlist/assets/css/yith-wcwl-user-panel.css?ver=yith-woocommerce-wishlist/assets/css/yith-wcwl-frontend.css?ver=yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl-functions.js?ver=yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl-add-to-wishlist.js?ver=yith-woocommerce-wishlist/assets/js/yith-wcwl-frontend.js?ver=HTML / DOM Fingerprints
yith-wcwl-add-buttonyith-wcwl-wishlist-popupyith-wcwl-wishlist-viewyith-wcwl-wishlist-tableyith-wcwl-wishlist-itemyith-wcwl-remove-from-wishlistyith-wcwl-main-buttonyith-wcwl-product-already-in-wishlist+2 more<!-- YITH WooCommerce Wishlist :: Start --><!-- YITH WooCommerce Wishlist :: End --><!-- YITH Wishlist :: Start --><!-- YITH Wishlist :: End -->data-product-iddata-actiondata-wishlist-iddata-addtowishlistdata-yith-wcwl-ajaxyith_wcwl_l10nyith_wcwl_frontendYITH_WCWL_Frontend[yith_wcwl_wishlist][yith_wcwl_add_to_wishlist][yith_wcwl_wishlist_count]