SecAlerts
y

yith

Security Risk Profile

56
/100
medium

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 21, 2024 to present

18
Total CVEs
6
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
56/100
medium
🆕 1Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
2
High
4
Medium
12
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
CSRF
2
3
SQL Injection
2

Most Affected Products

1. YITH WooCommerce Wishlist3
2. YITH YITH WooCommerce Product Add-Ons2
3. YITH WooCommerce Ajax Search2
4. YITHEMES Yith Woocommerce Ajax Search Wordpress2
5. YITH YITH WooCommerce Request A Quote1

Recent Vulnerabilities

See more →
CVE-2026-95602
CVSS 6.5medium

WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object References (IDOR) vulnerability

Sep 23, 2026🔧 No Patch
CVE-2026-14359
CVSS 8.8high

YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user

Sep 9, 2026🔧 No Patch
CVE-2026-84238
CVSS 9.8critical

WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability

Sep 3, 2026🔧 No Patch
CVE-2022-44630
CVSS 4.6medium

WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-Site Request Forgery (CSRF)

Jun 11, 2026🔧 No Patch
CVE-2026-42383
CVSS 7.6high

WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection vulnerability

May 20, 2026🔧 No Patch
CVE-2026-4432
CVSS 6.5EPSS 0%medium

YITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR

Apr 10, 2026🔧 No Patch
CVE-2025-12427
CVSS 5.3medium

YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename

Nov 19, 2025🔧 No Patch
CVE-2025-12777
CVSS 5.3medium

YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion

Nov 19, 2025🔧 No Patch
CVE-2025-48111
CVSS 4.3medium

WordPress YITH PayPal Express Checkout for WooCommerce plugin <= 1.49.0 - Cross Site Request Forgery (CSRF) vulnerability

Jun 17, 2025
CVE-2025-5238
CVSS 6.4EPSS 0%medium

YITH WooCommerce Wishlist <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Jun 14, 2025🔧 No Patch

Monitor yith in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.