Stored XSS Vulnerability in YITH WooCommerce Wishlist Plugin for WordPress
CVE-2025-5238
6.4MEDIUM
What is CVE-2025-5238?
The YITH WooCommerce Wishlist plugin for WordPress has a vulnerability that allows authenticated users with Contributor-level access and above to exploit an insufficiently sanitized input. Specifically, the āidā parameter is vulnerable to Stored Cross-Site Scripting (XSS), which enables attackers to inject arbitrary web scripts. When any user accesses a page that has been tampered with, the injected scripts will execute, potentially compromising user data and site integrity.
Affected Version(s)
YITH WooCommerce Wishlist * <= 4.5.0