A dangerous vulnerability is currently threatening over 100,000 WordPress websites. If you use the “TI WooCommerce Wishlist” plugin, you need to act IMMEDIATELY!
What happened?
Security researchers at Patchstack discovered a critical vulnerability in the popular WordPress plugin “TI WooCommerce Wishlist.” This vulnerability received the maximum rating of 10 out of 10 on the CVSS scale - meaning maximum danger for your website!
The alarming part: no security update is in sight. The developers were contacted back in late March but haven’t responded to this day.
Are you affected? Check in 2 minutes
Step 1: Check your plugin list
- Log in to your WordPress dashboard
- Go to “Plugins” → “Installed Plugins”
- Look for “TI WooCommerce Wishlist”
Step 2: Check for additional risk The vulnerability only becomes actively dangerous if the “WC Fields Factory” plugin is also installed. Check for it in your plugin list too.
Do you have both plugins? IMMEDIATE DEACTIVATION REQUIRED!
How to protect yourself RIGHT NOW - step by step
Immediate action: deactivate the plugin
- Open your WordPress dashboard
- Click “Plugins” → “Installed Plugins”
- Search for “TI WooCommerce Wishlist”
- Click “Deactivate”
- Confirm deactivation
⚠️ Important: don’t delete the plugin entirely yet, in case you want to restore your wishlist data later.
Long-term solution: safe alternatives
Since it’s unclear when (or if) a security update will arrive, these alternatives are recommended:
- YITH WooCommerce Wishlist (over 1 million active installs)
- WooCommerce Wishlist Plugin (regularly updated)
- Wishlist Member (premium option with top-tier support)
Why is this vulnerability so dangerous?
Through this vulnerability, attackers can:
- Upload malicious files to your server
- Take full control of your website
- Steal customer data
- Abuse your website to distribute malware
- Destroy your SEO rankings through spam
The attack works via a broken upload function that can simply bypass security checks.
Additional security measures
Use this as an opportunity for a full security check:
- Update all plugins - go to “Dashboard” → “Updates”
- Update WordPress core - check whether the latest WordPress version is installed
- Create a backup - create a complete backup immediately and verify automatic backups are working
Your action steps
- ✅ Immediately: deactivate TI WooCommerce Wishlist
- ✅ Today: update all other plugins
- ✅ This week: install a safe wishlist alternative
- ✅ Long-term: professional maintenance for automatic protection


