Where
-Infinity
0

Vendor Risk Score

See how yithemes compares to other vendors in security performance

View Risk Score →

Software

yithemes yith woocommerce product add-ons wordpress
4
yithemes yith maintenance mode wordpress
3
yithemes yith woocommerce ajax search wordpress
3
yithemes yith woocommerce gift cards wordpress
3
yithemes woocommerce account funds wordpress
1
yithemes woocommerce affiliate wordpress
1
yithemes yith advanced refund system for woocommerce wordpress
1
yithemes yith color and label variations for woocommerce wordpress
1
yithemes yith custom login
1
yithemes yith custom login wordpress
1
yithemes yith custom thank you page for woocommerce wordpress
1
yithemes yith desktop notifications for woocommerce wordpress
1
yithemes yith essential kit for woocommerce wordpress
1
yithemes yith paypal express checkout for woocommerce wordpress
1
yithemes yith pre-order for woocommerce wordpress
1
yithemes yith product size charts for woocommerce wordpress
1
yithemes yith woocommerce added to cart popup wordpress
1
yithemes yith woocommerce advanced reviews wordpress
1
yithemes yith woocommerce affiliates wordpress
1
yithemes yith woocommerce authorize.net payment gateway wordpress
1
yithemes yith woocommerce badge management wordpress
1
yithemes yith woocommerce best sellers wordpress
1
yithemes yith woocommerce brands add-on wordpress
1
yithemes yith woocommerce bulk product editing wordpress
1
yithemes yith woocommerce cart messages wordpress
1
yithemes yith woocommerce compare
1
yithemes yith woocommerce compare wordpress
1
yithemes yith woocommerce frequently bought together wordpress
1
yithemes yith woocommerce mailchimp wordpress
1
yithemes yith woocommerce multi vendor wordpress
1
yithemes yith woocommerce multi-step checkout wordpress
1
yithemes yith woocommerce order tracking wordpress
1
yithemes yith woocommerce pdf invoice and shipping list wordpress
1
yithemes yith woocommerce points and rewards wordpress
1
yithemes yith woocommerce popup
1
yithemes yith woocommerce product bundles wordpress
1
yithemes yith woocommerce questions and answers wordpress
1
yithemes yith woocommerce quick view wordpress
1
yithemes yith woocommerce recover abandoned cart wordpress
1
yithemes yith woocommerce request a quote wordpress
1
yithemes yith woocommerce social login wordpress
1
yithemes yith woocommerce stripe wordpress
1
yithemes yith woocommerce subscription wordpress
1
yithemes yith woocommerce tab manager wordpress
1
yithemes yith woocommerce waiting list wordpress
1
yithemes yith woocommerce wishlist wordpress
1
yithemes yith woocommerce zoom magnifier wordpress
1
Severity
4.3
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup allows Cross Site Request Forgery. This issue affects YITH WooCommerce Popup: from n/a through 1.48.0.

1 / 2
Source: NVD

Remedy

Update the WordPress YITH WooCommerce Popup plugin to the latest available version (at least 1.48.1).
First published (updated )
Severity
7.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.14.1.

Remedy

Update to 4.14.2 or a higher version.
First published (updated )
Severity
5.4
EPSS
0.04%
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbitrary scripts.

First published (updated )
Severity
6.1
EPSS
0.05%
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of addqueryarg without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

First published (updated )
Severity
4.3
EPSS
0.07%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activatemodule', 'deactivatemodule', and 'installmodule' functions in all versions up to, and including, 2.34.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate, and deactivate plugins from a pre-defined list of available YITH plugins.

First published (updated )
Severity
5.3
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.9.2.

Remedy

Update to 4.9.3 or a higher version.
First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.

Remedy

Update to 1.34.0 or a higher version.
First published (updated )
Severity
5.9
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Tab Manager yith-woocommerce-tab-manager.This issue affects YITH WooCommerce Tab Manager: from n/a through <= 1.35.0.

Remedy

Update to 1.35.1 or a higher version.
First published (updated )
Severity
5.9
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH Custom Login yith-custom-login.This issue affects YITH Custom Login: from n/a through <= 1.7.0.

Remedy

Update to 1.7.1 or a higher version.
First published (updated )
Severity
7.2
EPSS
0.05%
XSS
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

First published (updated )
Severity
4.3
EPSS
0.04%
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare.This issue affects YITH WooCommerce Compare: from n/a through <= 2.37.0.

Remedy

Update to 2.38.0 or a higher version.
First published (updated )
Severity
9.1
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

Remedy

Update to 4.3.1 or a higher version.
First published (updated )
Severity
9.8
Malicious File Upload
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.

1 / 2

Remedy

Update to 3.20.0 or higher version.
First published (updated )
Severity
6.1
XSS, CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well as does not sanitize its settings, which enables an unauthenticated attacker to inject malicious XSS payloads into the settings page of the plugin.

First published (updated )
Severity
6.9
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 - "Newsletter" tab, &yithmaintenancenewslettersubmitlabel parameter: payload should start with a single quote (') symbol to break the context, i.e.: NOTIFY ME' autofocus onfocus=alert(/Visse/);// v=' - this payload will be auto triggered while admin visits this page/tab. 2 - "General" tab issues, vulnerable parameters: &yithmaintenancemessage, &yithmaintenancecustomstyle, &yithmaintenancemascotte, &yithmaintenancetitlefont[size], &yithmaintenancetitlefont[family], &yithmaintenancetitlefont[color], &yithmaintenanceparagraphfont[size], &yithmaintenanceparagraphfont[family], &yithmaintenanceparagraphfont[color], &yithmaintenancebordertop. 3 - "Background" tab issues, vulnerable parameters: &yithmaintenancebackgroundimage, &yithmaintenancebackgroundcolor. 4 - "Logo" tab issues, vulnerable parameters: &yithmaintenancelogoimage, &yithmaintenancelogotagline, &yithmaintenancelogotaglinefont[size], &yithmaintenancelogotaglinefont[family], &yithmaintenancelogotaglinefont[color]. 5 - "Newsletter" tab issues, vulnerable parameters: &yithmaintenancenewsletteremailfont[size], &yithmaintenancenewsletteremailfont[family], &yithmaintenancenewsletteremailfont[color], &yithmaintenancenewslettersubmitfont[size], &yithmaintenancenewslettersubmitfont[family], &yithmaintenancenewslettersubmitfont[color], &yithmaintenancenewslettersubmitbackground, &yithmaintenancenewslettersubmitbackgroundhover, &yithmaintenancenewslettertitle, &yithmaintenancenewsletteraction, &yithmaintenancenewsletteremaillabel, &yithmaintenancenewsletteremailname, &yithmaintenancenewslettersubmitlabel, &yithmaintenancenewsletterhiddenfields. 6 - "Socials" tab issues, vulnerable parameters: &yithmaintenancesocialsfacebook, &yithmaintenancesocialstwitter, &yithmaintenancesocialsgplus, &yithmaintenancesocialsyoutube, &yithmaintenancesocialsrss, &yithmaintenancesocialsskype, &yithmaintenancesocialsemail, &yithmaintenancesocialsbehance, &yithmaintenancesocialsdribble, &yithmaintenancesocialsflickr, &yithmaintenancesocialsinstagram, &yithmaintenancesocialspinterest, &yithmaintenancesocialstumblr, &yithmaintenancesocialslinkedin.

Remedy

Update to 1.4.0 or higher version.
First published (updated )
Severity
6.9
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yithmaintenancenewslettersubmitlabel. Possible even when unfiltered HTML is disallowed by WordPress configuration.

Remedy

Update to 1.3.8 or higher version.
First published (updated )
Severity
9.8
Malicious File Upload
AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even though the intention was to only allow uploads of Gift Card images.

First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

First published (updated )
Severity
6.5
XSS, CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panelpage parameter.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203