CVE-2025-9207: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-9207 is an HTML Injection vulnerability in the TI WooCommerce Wishlist plugin for WordPress, affecting all versions up to and including 2.10.0. The flaw allows unauthenticated remote attackers to inject arbitrary HTML into wishlist items by exploiting unvalidated hidden form fields. It was published on December 13, 2025, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is improper input validation (CWE-20): the plugin accepts hidden form fields without restricting or sanitizing the values, which are subsequently rendered in the browser without encoding. This allows an unauthenticated attacker to submit crafted HTTP requests containing arbitrary HTML markup that is stored and later displayed to users viewing wishlist items. The vulnerable code paths are located in includes/wishlist.class.php at lines 326 and 544 of the plugin's source (Wordfence, WordPress Trac).

Impact

Successful exploitation enables unauthenticated attackers to inject arbitrary HTML content into wishlist items visible to other users, facilitating UI redressing, phishing lures, or defacement of product/wishlist pages. The vulnerability has no direct impact on confidentiality or availability, but the integrity of page content is compromised (CVSS integrity impact: Low). While not a full cross-site scripting vulnerability, injected HTML can be leveraged to deceive users or redirect them to malicious resources (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-9207. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.072% (0.000720), indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities catalog (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the TI WooCommerce Wishlist plugin version 2.10.0 or earlier using tools like WPScan or by inspecting plugin directories.
  2. Locate wishlist item submission: Navigate to a product page on the target WooCommerce store and add an item to a wishlist, intercepting the HTTP request with a proxy tool such as Burp Suite.
  3. Tamper with hidden fields: Modify the hidden form field values in the intercepted request to include arbitrary HTML markup (e.g., <a href="https://malicious.example.com">Click here</a> or <img src=x onerror=...>).
  4. Submit the crafted request: Forward the modified request to the server; the plugin stores the unsanitized HTML value without restriction.
  5. Trigger victim rendering: When another user (or an administrator) views the affected wishlist, the injected HTML is rendered in their browser, potentially enabling phishing, UI redressing, or further social engineering (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: Web server access logs showing POST requests to WooCommerce wishlist endpoints (e.g., /wp-admin/admin-ajax.php with wishlist-related action parameters) containing HTML tags (<, >, href=, src=) in field values.
  • Database: Unexpected HTML markup stored in the wishlist items table (typically wp_tinvwl_wishlist_item or similar) in the WordPress database.
  • Network: Outbound links or image load requests originating from wishlist pages pointing to external or suspicious domains, visible in browser network logs or WAF telemetry.

Mitigation and workarounds

Update the TI WooCommerce Wishlist plugin to version 2.10.1 or later, which addresses the vulnerability by restricting and sanitizing hidden field values before output. The fix is available via the WordPress plugin repository changeset (WordPress Trac Changeset). As a temporary workaround, site administrators can use a Web Application Firewall (WAF) to block requests containing HTML tags in wishlist-related form fields, or disable the wishlist feature until the plugin is updated (Wordfence).

Community reactions

Sucuri included CVE-2025-9207 in their December 2025 vulnerability patch roundup, highlighting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management