CVE-2026-82305: YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title
Published Sep 11, 2026
·Updated
The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
Affected Software
1 affected component
YITH WooCommerce Wishlist<4.18.1
Event History
Sep 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which installations are exposed?
Sites using YITH WooCommerce Wishlist versions earlier than 4.18.1 are affected.
2
Does exploitation require a WordPress account or wishlist ownership?
No. An unauthenticated attacker can exploit the issue because authorization to rename the targeted wishlist is not verified.
3
What is the impact of a successful exploit?
An attacker can rename any wishlist on the site, including wishlists they do not own.
4
What is the available remediation?
Update YITH WooCommerce Wishlist to version 4.18.1 or later.