PatchSiren

YITH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM YITH CVE published 2026-09-11

CVE-2026-82305

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Defenders should assess exposure and prioritize updating to version 4.18.1 or later. The vulnerability allows unauthenticated users to rename [truncated]

MEDIUM YITH CVE published 2026-06-11

CVE-2022-44630

A Cross-Site Request Forgery (CSRF) vulnerability exists in YITH WooCommerce Product Slider Carousel, affecting versions from n/a through 1.16.0. This issue allows for Cross-Site Request Forgery. The CVE record was published on 2026-06-11T10:16:20.870Z and has not been modified since then. The NVD entry is currently Deferred. Defenders and administrators of YITH WooCommerce Product Slider Carousel install [truncated]

HIGH YITH CVE published 2026-05-20

CVE-2026-42383

CVE-2026-42383 is a high-severity blind SQL injection issue in YITH WooCommerce Product Add-Ons, affecting versions through 4.29.0. The supplied CVSS vector indicates network exposure with high privileges required and no user interaction, with confidentiality impact rated high.