
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-9207 is an HTML Injection vulnerability in the TI WooCommerce Wishlist plugin for WordPress, affecting all versions up to and including 2.10.0. The flaw allows unauthenticated remote attackers to inject arbitrary HTML into wishlist items by exploiting unvalidated hidden form fields. It was published on December 13, 2025, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is improper input validation (CWE-20): the plugin accepts hidden form fields without restricting or sanitizing the values, which are subsequently rendered in the browser without encoding. This allows an unauthenticated attacker to submit crafted HTTP requests containing arbitrary HTML markup that is stored and later displayed to users viewing wishlist items. The vulnerable code paths are located in includes/wishlist.class.php at lines 326 and 544 of the plugin's source (Wordfence, WordPress Trac).
Successful exploitation enables unauthenticated attackers to inject arbitrary HTML content into wishlist items visible to other users, facilitating UI redressing, phishing lures, or defacement of product/wishlist pages. The vulnerability has no direct impact on confidentiality or availability, but the integrity of page content is compromised (CVSS integrity impact: Low). While not a full cross-site scripting vulnerability, injected HTML can be leveraged to deceive users or redirect them to malicious resources (Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-9207. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.072% (0.000720), indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities catalog (Wordfence).
<a href="https://malicious.example.com">Click here</a> or <img src=x onerror=...>)./wp-admin/admin-ajax.php with wishlist-related action parameters) containing HTML tags (<, >, href=, src=) in field values.wp_tinvwl_wishlist_item or similar) in the WordPress database.Update the TI WooCommerce Wishlist plugin to version 2.10.1 or later, which addresses the vulnerability by restricting and sanitizing hidden field values before output. The fix is available via the WordPress plugin repository changeset (WordPress Trac Changeset). As a temporary workaround, site administrators can use a Web Application Firewall (WAF) to block requests containing HTML tags in wishlist-related form fields, or disable the wishlist feature until the plugin is updated (Wordfence).
Sucuri included CVE-2025-9207 in their December 2025 vulnerability patch roundup, highlighting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."