CVE 5.3 MEDIUM

TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection_CVE-2025-9207

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject arbitrary HTML into wishlist items.

Basic Information

ID CVE-2025-9207
Source Wordfence
Published Dec 13, 2025 at 07:21

Affected Product

Vendor templateinvaders
Product TI WooCommerce Wishlist
Version *
Affected Versions templateinvaders TI WooCommerce Wishlist *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.