SecAlerts
y

yith

Security Risk Profile

54
/100
medium

Security Risk Score

Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 21, 2024 to present

16
Total CVEs
5
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
54/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
2
High
3
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
CSRF
2
3
SQL Injection
2

Most Affected Products

1. YITH WooCommerce Wishlist3
2. YITH YITH WooCommerce Product Add-Ons2
3. YITH WooCommerce Ajax Search2
4. YITHEMES Yith Woocommerce Ajax Search Wordpress2
5. YITH YITH Request a Quote for WooCommerce Premium1

Recent Vulnerabilities

See more →
CVE-2026-84238
CVSS 9.8critical

WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability

Sep 3, 2026🔧 No Patch
CVE-2022-44630
CVSS 4.6medium

WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-Site Request Forgery (CSRF)

Jun 11, 2026🔧 No Patch
CVE-2026-42383
CVSS 7.6high

WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection vulnerability

May 20, 2026🔧 No Patch
CVE-2026-4432
CVSS 6.5EPSS 0%medium

YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR

Apr 10, 2026🔧 No Patch
CVE-2025-12427
CVSS 5.3medium

YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename

Nov 19, 2025🔧 No Patch
CVE-2025-12777
CVSS 5.3medium

YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion

Nov 19, 2025🔧 No Patch
CVE-2025-48111
CVSS 4.3medium

WordPress YITH PayPal Express Checkout for WooCommerce plugin <= 1.49.0 - Cross Site Request Forgery (CSRF) vulnerability

Jun 17, 2025
CVE-2025-5238
CVSS 6.4EPSS 0%medium

YITH WooCommerce Wishlist <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Jun 14, 2025🔧 No Patch
CVE-2023-36506
CVSS 5.3medium

WordPress YITH WooCommerce Waitlist plugin <= 2.13.0 - Broken Access Control vulnerability

Dec 13, 2024
CVE-2024-47350
CVSS 9.3critical

WordPress YITH WooCommerce Ajax Search plugin <= 2.8.0 - SQL Injection vulnerability

Oct 6, 2024

Monitor yith in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

yith Security Vulnerabilities & Risk Score | 16 CVEs | SecAlerts - SecAlerts