WordPress Maintenance

URGENT: Critical WordPress Vulnerability – 100,000+ Websites at Risk!

by Sven Kilcher·

A critical WordPress vulnerability threatens 100,000+ websites. Disable TI WooCommerce Wishlist immediately! ✓ Step-by-step guide ✓ Free security check

URGENT: Critical WordPress Vulnerability – 100,000+ Websites at Risk!

A dangerous vulnerability is currently threatening over 100,000 WordPress websites. If you use the “TI WooCommerce Wishlist” plugin, you need to act IMMEDIATELY!

What happened?

Security researchers at Patchstack discovered a critical vulnerability in the popular WordPress plugin “TI WooCommerce Wishlist.” This vulnerability received the maximum rating of 10 out of 10 on the CVSS scale - meaning maximum danger for your website!

The alarming part: no security update is in sight. The developers were contacted back in late March but haven’t responded to this day.

Are you affected? Check in 2 minutes

Step 1: Check your plugin list

  1. Log in to your WordPress dashboard
  2. Go to “Plugins” → “Installed Plugins”
  3. Look for “TI WooCommerce Wishlist”

Step 2: Check for additional risk The vulnerability only becomes actively dangerous if the “WC Fields Factory” plugin is also installed. Check for it in your plugin list too.

Do you have both plugins? IMMEDIATE DEACTIVATION REQUIRED!

How to protect yourself RIGHT NOW - step by step

Immediate action: deactivate the plugin

  1. Open your WordPress dashboard
  2. Click “Plugins” → “Installed Plugins”
  3. Search for “TI WooCommerce Wishlist”
  4. Click “Deactivate”
  5. Confirm deactivation

⚠️ Important: don’t delete the plugin entirely yet, in case you want to restore your wishlist data later.

Long-term solution: safe alternatives

Since it’s unclear when (or if) a security update will arrive, these alternatives are recommended:

  • YITH WooCommerce Wishlist (over 1 million active installs)
  • WooCommerce Wishlist Plugin (regularly updated)
  • Wishlist Member (premium option with top-tier support)

Why is this vulnerability so dangerous?

Through this vulnerability, attackers can:

  • Upload malicious files to your server
  • Take full control of your website
  • Steal customer data
  • Abuse your website to distribute malware
  • Destroy your SEO rankings through spam

The attack works via a broken upload function that can simply bypass security checks.

Additional security measures

Use this as an opportunity for a full security check:

  1. Update all plugins - go to “Dashboard” → “Updates”
  2. Update WordPress core - check whether the latest WordPress version is installed
  3. Create a backup - create a complete backup immediately and verify automatic backups are working

Your action steps

  1. Immediately: deactivate TI WooCommerce Wishlist
  2. Today: update all other plugins
  3. This week: install a safe wishlist alternative
  4. Long-term: professional maintenance for automatic protection
FAQ

Das willst du wissen

How do I know if my website has already been hacked?
Typical signs are: slow load times, unknown admin users, suspicious files in the wp-content folder, redirects to unfamiliar websites, or warnings from Google. If in doubt, I run a free malware scan.
Can I just delete the plugin, or do I need to deactivate it?
Deactivate it first, so you don't lose your wishlist data. Once you've installed a safe alternative, you can remove it entirely. I'm happy to help you switch over safely.
My website is slow - could that be related to this vulnerability?
Possibly, but not necessarily. Slow websites often have multiple causes: outdated plugins, missing caching optimization, or malware. A professional analysis uncovers all the issues.
How often do critical vulnerabilities like this happen?
More often than you'd think, unfortunately. In 2024 alone, there were over 15 critical WordPress plugin vulnerabilities. That's exactly why continuous monitoring through a maintenance service matters so much - you can't keep an eye on every threat yourself.
What does it cost if my website gets hacked?
Cleaning up a hacked website costs between €500-2,000, plus lost revenue, SEO damage, and loss of trust. A preventive maintenance service for €40/month is a bargain by comparison.
Sven Kilcher – WordPress Freelancer
WordPress Freelancer

Die WP Helping Hand, WordPress Freelancer

Sven Kilcher

Ich bin Sven, dein erfahrener Partner für alles rund um WordPress. Mit über 8 Jahren Expertise und mehr als 120 zufriedenen Kunden stehe ich dir zur Seite, um deine Website professionell zu gestalten, zu warten und weiterzuentwickeln. Ob es um maßgeschneiderte Lösungen oder regelmäßige Wartungen geht – ich bin für dich da.

44
Alter
8 Jahre
Erfahrung
120+
Kunden
50+
Wartungen