+38 067 569 61 50

info@clapkey.com

100,000 Websites at Risk Due to Vulnerability in Wishlist Plugin 🎹

100,000 Websites at Risk Due to Vulnerability in Wishlist Plugin 🎹

100,000 websites at risk due to a vulnerability in the Wishlist 🎹

Analysts have discovered a critical vulnerability (CVE-2025-47577) in the popular TI WooCommerce Wishlist plugin that allows hackers to upload malicious files to a site without authorization. The plugin lets online store customers save favorite products for later purchase.

🔍 The core of the problem

- Vulnerability: File type check bypass (parameter test_type=false)

- Attack conditions: The WC Fields Factory plugin must be active + integration with Wishlist must be enabled

- Danger: Ability to upload PHP files and achieve remote code execution (RCE)

- Risk: 10/10 on the CVSS scale

Great plugin! It adds not only products to the wishlist, but backdoors too 😅

This page has been translated partially or fully using AI. Please send any translation feedback to info@clapkey.com.

#StandWithUkraine

Support the Armed Forces of Ukraine during the Russian invasion

Contacts

Office

4th floor, Metropoliten Shopping Center (38 Gogolya St.), Poltava, Ukraine, 36000