100,000 Websites at Risk Due to Vulnerability in Wishlist Plugin 🎹
100,000 websites at risk due to a vulnerability in the Wishlist 🎹
Analysts have discovered a critical vulnerability (CVE-2025-47577) in the popular TI WooCommerce Wishlist plugin that allows hackers to upload malicious files to a site without authorization. The plugin lets online store customers save favorite products for later purchase.
🔍 The core of the problem
- Vulnerability: File type check bypass (parameter test_type=false)
- Attack conditions: The WC Fields Factory plugin must be active + integration with Wishlist must be enabled
- Danger: Ability to upload PHP files and achieve remote code execution (RCE)
- Risk: 10/10 on the CVSS scale
Great plugin! It adds not only products to the wishlist, but backdoors too 😅


