Executive brief
The MC Woocommerce Wishlist plugin for WordPress, which allows customers to save products for later purchase, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site visitor or administrator clicks a specially crafted link, the attacker can execute code in their browser, potentially leading to unauthorized redirects, theft of session information, or website defacement. This vulnerability can be exploited by remote attackers without needing to log in to the site.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the MC Woocommerce Wishlist plugin for WordPress (versions <= 1.9.19) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Successful exploitation requires a victim (such as a site administrator) to interact with a malicious link or crafted page (UI:R). The vulnerability has a CVSS 3.1 base score of 7.1, reflecting its potential to impact confidentiality, integrity, and availability within the victim's browser context. The issue is resolved in version 1.9.20.
Affected products
- Moreconvert Team MC Woocommerce Wishlist <= 1.9.19
Timeline
- 2026-06-04: other: Reported by researcher manop55555
- 2026-07-01: advisory: Patchstack advisory published
- 2026-07-02: disclosed: NVD publication date
- 2026-07-02: patched: Version 1.9.20 released to address the vulnerability