TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 - Arbitrary Options Update
Summary
| CVE | CVE-2020-36725 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-07 02:15:12 UTC |
| Updated | 2026-04-08 19:17:35 UTC |
| Description | The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise restricted access to the vulnerable blog and update any settings. |
Risk And Classification
Primary CVSS: v3.1 8.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS: 0.005720000 probability, percentile 0.686900000 (date 2026-04-09)
Problem Types: CWE-862 | CWE-862 CWE-862 Missing Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Templateinvaders | Ti Woocommerce Wishlist | All | All | All | All |
| Application | Templateinvaders | Ti Woocommerce Wishlist | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TemplateInvaders | TI WooCommerce Wishlist Pro | affected 1.21.4 semver | Not specified |
| CNA | Templateinvaders | TI WooCommerce Wishlist | affected 1.21.11 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TI WooCommerce Wishlist - Authenticated WP Options Change WordPress Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | wpscan.com | Third Party Advisory |
| TI WooCommerce Wishlist <= 1.21.11 and TI WooCommerce Wishlist Pro <= 1.21.4 - Arbitrary Options Update | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| Changelog - TI WooCommerce Wishlist - TemplateInvaders | af854a3a-2127-422b-91ae-364da2661108 | templateinvaders.com | Release Notes |
| Critical zero-day vulnerability fixed in WordPress TI WooCommerce Wishlist plugin. – NinTechNet | af854a3a-2127-422b-91ae-364da2661108 | blog.nintechnet.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jerome Bruandet (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2020-10-16T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.