Yithemes develops a suite of WordPress and WooCommerce plugins focused on product customization, merchandising, and store management, offering extended functionality to e-commerce platforms. Its vulnerabilities skew toward serious outcomes and recur across its plugin line through web-application weakness classes including cross-site scripting, missing authorization checks, unrestricted file uploads, cross-site request forgery, and unsafe deserialization—exposure patterns typical of plugins that handle user input, file management, and administrative operations. Defenders should treat updates to this vendor's plugins as priority patching, particularly where plugins interact with user-facing storefront or administrative interfaces; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yithemes over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3120CRITICAL An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the | Feb 22, 2021 | 9.8 | 51 | NO | NO |
CVE-2022-45359CRITICAL Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. | Dec 6, 2022 | 9.8 | 37 | NO | NO |
CVE-2024-4455MEDIUM The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insuffici | May 24, 2024 | 6.1 | 29 | NO | YES |
CVE-2024-47350CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue | Oct 6, 2024 | 9.3 | 27 | NO | NO |
CVE-2024-30470HIGH Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-49777HIGH Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0. | Dec 31, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-24366MEDIUM Missing Authorization vulnerability in YITHEMES YITH WooCommerce Request A Quote yith-woocommerce-request-a-quote allows Exploiting Incorrectly Configured Access Control Security L | Jan 22, 2026 | 5.3 | 22 | NO | NO |
CVE-2025-8617MEDIUM The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_quick_view shortcode in all versions up to, and including, 2 | Dec 13, 2025 | 6.4 | 22 | NO | NO |
CVE-2024-47367HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons all | Oct 6, 2024 | 7.1 | 21 | NO | NO |
CVE-2025-12777MEDIUM The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verify | Nov 19, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yithemes.
Media articles that mention a CVE ID that affects a product developed by Yithemes — matched by CVE ID, not by vendor name.