Templateinvaders develops a niche e-commerce plugin for WooCommerce focused on wishlist functionality, with observed vulnerabilities centered on SQL injection and missing authorization controls in that product. These are characteristic input-handling and access-control weaknesses in web-facing plugins; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Templateinvaders over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0412CRITICAL The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using | Feb 28, 2022 | 9.8 | 79 | NO | YES |
CVE-2024-43917CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affec | Aug 29, 2024 | 9.8 | 62 | NO | YES |
CVE-2025-47577CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web Shell to a Web Server.This iss | May 19, 2025 | 10.0 | 45 | NO | YES |
CVE-2020-36725HIGH The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1. | Jun 7, 2023 | 8.1 | 24 | NO | NO |
CVE-2024-10567HIGH The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to | Dec 4, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-9156HIGH The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient prepara | Oct 10, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-67929MEDIUM Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This | Dec 16, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-9207MEDIUM The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and | Dec 13, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-58247MEDIUM Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This | Sep 22, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-32920MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Stored | May 19, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Templateinvaders.
Media articles that mention a CVE ID that affects a product developed by Templateinvaders — matched by CVE ID, not by vendor name.