Vulnerabilities > Wpclever > WPC Smart Wishlist FOR Woocommerce > 2.9.6

DATE CVE VULNERABILITY TITLE RISK
2023-11-09 CVE-2023-34386 Cross-Site Request Forgery (CSRF) vulnerability in Wpclever WPC Smart Wishlist for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
network
low complexity
wpclever CWE-352
8.8
2022-05-16 CVE-2022-1465 Cross-site Scripting vulnerability in Wpclever WPC Smart Wishlist for Woocommerce
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue.
network
wpclever CWE-79
4.3