The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Defenders should assess exposure and prioritize updating to version 4.18.1 or later. The vulnerability allows unauthenticated users to rename [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in YITH WooCommerce Product Slider Carousel, affecting versions from n/a through 1.16.0. This issue allows for Cross-Site Request Forgery. The CVE record was published on 2026-06-11T10:16:20.870Z and has not been modified since then. The NVD entry is currently Deferred. Defenders and administrators of YITH WooCommerce Product Slider Carousel install [truncated]
CVE-2026-42383 is a high-severity blind SQL injection issue in YITH WooCommerce Product Add-Ons, affecting versions through 4.29.0. The supplied CVSS vector indicates network exposure with high privileges required and no user interaction, with confidentiality impact rated high.