WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Wishlist

Add wishlist feature to your WooCommerce product or any post types.

9Reported vulnerabilities
6.5Highest CVSS score
1.0.46Latest version
400+Active installs

What to do now

Update Wishlist to 1.0.44 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 8, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-32618 Medium 6.5 0.5% 1.0.44 and earlier April 9, 2025
CVE-2024-12809 Medium 6.4 0.3% 0 to 1.0.43 (inclusive) 1.0.44 March 7, 2025
CVE-2025-26915 Medium 6.5 0.4% 1.0.41 and earlier 1.0.42 February 23, 2025
CVE-2025-49075 Medium 6.4 0.2% 1.0.43 and earlier 1.0.44 May 30, 2025
CVE-2025-31061 Medium 6.1 0.3% 2.1.0 and earlier June 4, 2025
CVE-2025-24655 Medium 6.1 0.3% 1.0.39 and earlier 1.0.40 January 15, 2025
CVE-2025-31062 Medium 4.3 0.3% 2.1.0 and earlier May 16, 2025
CVE-2025-31063 Medium 4.3 0.3% 2.1.0 and earlier May 16, 2025
CVE-2025-32272 Medium 4.3 0.2% 1.0.44 and earlier April 4, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.