Access violation vulnerability in YITH WooCommerce Wishlist 4.10.0

The YITH WooCommerce Wishlist plugin for WordPress is at risk of being hacked in versions up to and including 4.10.0. This is because there is a lack of security checks on keys that are controlled by the user. As a result, unauthorized individuals can find out the ID for someone’s wishlist and change the name of the wishlist without permission. This could lead to various malicious actions such as changing the appearance of a store, tricking customers, or tampering with multiple user accounts.

Detected in:

YITH WooCommerce Wishlist fixed vulnerable versions: >= * <= 4.10.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.