Missing Authorization
3 records30%First: 2019. Latest: 2023.
Plugin security history
The Wordfence Intelligence dataset currently contains 10 vulnerability records associated with YITH WooCommerce Product Add-Ons, published between 2019 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 1 | |
| 2022 | 2 | |
| 2023 | 2 | |
| 2024 | 4 | |
| 2026 | 1 |
| Severity | Records | Share |
|---|---|---|
| High | 1 | 10% |
| Medium | 9 | 90% |
First: 2019. Latest: 2023.
First: 2024. Latest: 2024.
First: 2023. Latest: 2024.
First: 2022. Latest: 2022.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.29.14.14.24.13.14.9.34.6.04.3.14.2.12.16.01.5.23Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.29.0 | YITH WooCommerce Product Add-Ons <= 4.29.0 - Authenticated (Shop manager+) SQL Injection | May 20, 2026 | 4.29.1 | Medium |
*-4.14.1 | YITH WooCommerce Product Add-Ons <= 4.14.1 - Reflected Cross-Site Scripting | October 24, 2024 | 4.14.2 | Medium |
*-4.13.0 | YITH WooCommerce Product Add-Ons <= 4.13.0 - Reflected Cross-Site Scripting | September 30, 2024 | 4.13.1 | Medium |
*-4.9.2 | YITH WooCommerce Product Add-Ons <= 4.9.2 - Unauthenticated Content Injection | June 6, 2024 | 4.9.3 | Medium |
*-4.5.0 | YITH WooCommerce Product Add-Ons <= 4.5.0 - Unuathenticated Cross-Site Scripting | March 15, 2024 | 4.6.0 | Medium |
[*, 4.3.1) | YITH WooCommerce Product Add-Ons <= 4.3.0 - Authenticated(Shop Manager+) PHP Object Injection | December 28, 2023 | 4.3.1 | Medium |
*-4.2.0 | YITH WooCommerce Product Add-Ons <= 4.2.0 - Missing Authorization | October 25, 2023 | 4.2.1 | Medium |
*-2.15.0 | YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery | November 11, 2022 | 2.16.0 | Medium |
*-2.15.0 | YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization | November 11, 2022 | 2.16.0 | High |
*-1.5.21 | YIT Plugin Framework <= 3.3.8 - Authenticated Settings Change | October 31, 2019 | 1.5.23 | Medium |
Selected source records
Published: May 20, 2026
Published: October 24, 2024
Published: September 30, 2024
Published: June 6, 2024
Published: March 15, 2024
Published: December 28, 2023
Published: October 25, 2023
Published: November 11, 2022
Published: November 11, 2022
Published: December 28, 2023
Published: October 24, 2024
Published: March 15, 2024
Published: September 30, 2024
Published: June 6, 2024
Published: October 25, 2023
Published: May 20, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.