CVE-2026-82305
YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
| Vendor | unknown |
| Product | yith woocommerce wishlist |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown yith woocommerce wishlist
Be the first to know when new medium vulnerabilities affecting unknown yith woocommerce wishlist are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / YITH WooCommerce Wishlist
0 < 4.18.1
References
Credits
Abdullah Kareem WPScan