Missing Authorization
4 records33.3%First: 2020. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 12 vulnerability records associated with TI WooCommerce Wishlist, published between 2020 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2020 | 1 | |
| 2022 | 1 | |
| 2023 | 2 | |
| 2024 | 3 | |
| 2025 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 33.3% |
| High | 3 | 25% |
| Medium | 5 | 41.7% |
First: 2020. Latest: 2025.
First: 2022. Latest: 2024.
First: 2023. Latest: 2025.
First: 2025. Latest: 2025.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.11.02.10.02.9.22.9.12.9.02.7.41.7.01.40.11.21.12Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.10.0 | TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection | December 12, 2025 | 2.11.0 | Medium |
*-2.10.0 | TI WooCommerce Wishlist <= 2.10.0 - Missing Authorization | November 21, 2025 | 2.11.0 | Medium |
*-2.10.0 | TI WooCommerce Wishlist <= 2.10.0 - Missing Authorization | September 22, 2025 | 2.11.0 | Medium |
*-2.9.2 | TI WooCommerce Wishlist <= 2.9.2 - Unauthenticated Arbitrary File Upload | May 16, 2025 | 2.10.0 | Critical |
*-2.10.0 | TI WooCommerce Wishlist <= 2.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 15, 2025 | 2.11.0 | Medium |
*-2.9.1 | TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access | December 3, 2024 | 2.9.2 | High |
*-2.9.0 | TI WooCommerce Wishlist <= 2.9.0 - Unauthenticated SQL Injection via 'lang' | September 19, 2024 | 2.9.1 | High |
*-2.8.2 | TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection | August 22, 2024 | 2.9.0 | Critical |
[*, 2.7.4) | TI WooCommerce Wishlist <= 2.7.3 - Unauthenticated Blind SQL Injection via Rest API | July 31, 2023 | 2.7.4 | Critical |
*-1.6.2 | Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get | July 18, 2023 | 1.7.0 | Medium |
[*, 1.40.1) | TI WooCommerce Wishlist / TI WooCommerce Wishlist Pro < 1.40.1 - Unauthenticated SQL Injection | January 31, 2022 | 1.40.1 | Critical |
*-1.21.11 | TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 - Arbitrary Options Update | October 16, 2020 | 1.21.12 | High |
Selected source records
Published: December 12, 2025
Published: November 21, 2025
Published: September 22, 2025
Published: May 16, 2025
Published: May 15, 2025
Published: December 3, 2024
Published: September 19, 2024
Published: August 22, 2024
Published: May 16, 2025
Published: August 22, 2024
Published: July 31, 2023
Published: January 31, 2022
Published: October 16, 2020
Published: December 3, 2024
Published: September 19, 2024
Published: September 22, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.