WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in MoreConvert Wishlist for WooCommerce

Free: WC Wishlist, Email automation, Elementor Widgets. Premium: Back-in-Stock Notifier, Save for Later, Multi-lists, Reports, Email Marketing.

8Reported vulnerabilities
9.8Highest CVSS score
1.9.21Latest version
8,000+Active installs

What to do now

Update MoreConvert Wishlist for WooCommerce to 1.9.20 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 7, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-5722 Critical 9.8 0.5% 0 to 1.9.14 (inclusive) 1.9.15 May 5, 2026
CVE-2024-13694 High 7.5 0.6% Before 1.8.8 1.8.8 January 30, 2025
CVE-2026-57356 High 7.2 0.3% 1.9.19 and earlier 1.9.20 July 1, 2026
CVE-2025-47487 Medium 6.1 0.3% 1.9.1 and earlier 1.9.2 June 4, 2025
CVE-2024-34819 Medium 5.3 0.4% 1.7.2 and earlier 1.7.3 May 9, 2024
CVE-2024-34813 Medium 5.3 0.3% 1.7.8 and earlier 1.7.9 May 9, 2024
CVE-2025-30879 Medium 4.9 0.6% 1.8.9 and earlier 1.9.0 March 27, 2025
WF-7c7f6ef2-6c50-4739-8844-0db7d9ffe7f7 Medium 4.3 1.5.4 and earlier 1.5.5 April 10, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.