CVE-2026-57356: MC Woocommerce Wishlist Unauthenticated XSS Vulnerability (v1.9.19 and Earlier)
A cross-site scripting (XSS) vulnerability exists in MC Woocommerce Wishlist plugin versions 1.9.19 and earlier. An attacker can inject malicious scripts that execute in a visitor's browser without needing any authentication or special access to the plugin. If a site admin or customer visits a compromised wishlist page, the attacker's code runs in their session, potentially stealing session tokens, modifying page content, or redirecting users to malicious sites.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.1 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-02 / 2026-07-02
NVD description (verbatim)
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-57356 is an unauthenticated reflected or stored XSS flaw in MC Woocommerce Wishlist affecting versions up to 1.9.19. The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). With a CVSS 3.1 score of 7.1 (HIGH), the attack vector is network-based, requires no privileges, and involves minimal complexity. The impact spans confidentiality, integrity, and availability due to the cross-site nature (scope change) of the vulnerability. User interaction is required—an admin or customer must visit a malicious link or page—but the network accessibility and lack of authentication significantly lower the barrier to exploitation.
Business impact
An XSS vulnerability in a wishlist plugin poses direct risk to customer trust and data security. Attackers could harvest session cookies or authentication tokens from site visitors, leading to account takeover. Customer personal information, purchase history, or payment details could be exposed or manipulated. Additionally, the plugin's use across multiple Woocommerce sites means a single exploit could affect many merchants simultaneously if the vulnerability becomes widely known or weaponized. Regulatory exposure (PCI DSS, GDPR) may apply if customer data is compromised.
Affected systems
MC Woocommerce Wishlist plugin versions 1.9.19 and earlier are vulnerable. Any Woocommerce store using an affected version of this plugin is at risk. The vulnerability can be exploited against site visitors (customers, admins) regardless of their privilege level, making the exposure broad across any traffic to wishlist pages or features.
Exploitability
Exploitation is straightforward and requires no authentication. An attacker crafts a malicious URL or injects a payload into a wishlist page and tricks or socially engineers a site visitor into clicking the link or viewing the page. The low complexity and network accessibility make this vulnerability attractive to attackers. No known exploit is currently listed in the CISA KEV catalog, but the attack surface is large and the technique is well-understood in the security community.
Remediation
Update MC Woocommerce Wishlist to a patched version newer than 1.9.19 as soon as possible. Verify the exact patch version in the official plugin repository or vendor advisory. Additionally, implement Web Application Firewall (WAF) rules to detect and block XSS payloads targeting wishlist endpoints as a temporary mitigation. Consider disabling the wishlist feature entirely until patching is confirmed if the plugin is not actively maintained or updates are delayed.
Patch guidance
Contact the MC Woocommerce Wishlist vendor or check the WordPress plugin repository for available updates beyond version 1.9.19. Apply the update in a staging environment first to verify compatibility with your Woocommerce installation and any custom code. After patching, test wishlist functionality and re-enable the plugin. If the vendor has not released a patch, consider switching to an alternative, actively maintained wishlist plugin.
Detection guidance
Monitor web server and WAF logs for unusual patterns in wishlist page requests, particularly those containing script tags, event handlers (onclick, onerror), or URL-encoded payloads. Use your SIEM to correlate suspicious requests from external IPs with subsequent admin or customer activity. Check plugin version using your site's admin dashboard or a WordPress security scanner. Inspect published wishlist URLs and page source code for unexpected JavaScript, particularly in user-controlled fields (product names, descriptions, custom attributes).
Why prioritize this
Although not yet in the CISA KEV catalog, this HIGH-severity vulnerability warrants rapid patching because it is unauthenticated, affects a plugin used across many Woocommerce stores, and enables account compromise or data theft. The low complexity and network accessibility mean an attacker can exploit it at scale once the vulnerability is publicly disclosed or added to exploit databases. Prioritize this above patch management for lower-severity issues but coordinate with your vendor to confirm patch availability.
Risk score, explained
The CVSS 3.1 score of 7.1 reflects a HIGH severity rating. The score is driven by network-based attack vector, no authentication required, and cross-site scope (affecting both confidentiality and integrity). Although user interaction is required to trigger the exploit, the combination of low barriers to entry, broad exposure (any site visitor can be targeted), and real-world impact on customer data and site integrity justifies the elevated score. The lack of a known exploit in active use and absence from the KEV catalog do not reduce the inherent risk.
Frequently asked questions
Do I need to wait for CISA to add this to the KEV catalog before I patch?
No. KEV catalog inclusion indicates active exploitation in the wild, but it is not a prerequisite for patching. This vulnerability is unauthenticated and affects a widely used plugin, making it attractive to attackers. Patch proactively based on severity and exposure rather than waiting for KEV listing.
Can I use a WAF to fully protect against this vulnerability?
A WAF can provide temporary mitigation by blocking common XSS payloads, but it is not a substitute for patching. WAF rules may be bypassed with encoding tricks or zero-day payloads. Deploy WAF rules as a short-term defense while you prepare and test the actual plugin update.
What should I do if the plugin vendor has not released a patch?
If the vendor is unresponsive or the plugin is abandoned, disable the wishlist feature or uninstall the plugin entirely. Then evaluate alternative wishlist solutions from active, reputable vendors. Leaving an unpatched XSS vulnerability in production poses ongoing risk.
Can customers or non-admin users be harmed by this vulnerability?
Yes. Any site visitor, including customers, can be targeted by an XSS exploit. An attacker could harvest their session tokens, manipulate their wishlist, redirect them to phishing sites, or steal personal data. Administrators are equally at risk and may face even greater impact if their admin session is compromised.
This analysis is for informational purposes and represents the state of the vulnerability as of the published date. No exploit code or weaponized proof-of-concept is provided. Patch availability and version numbers should be verified against the official MC Woocommerce plugin repository and vendor advisories. CVSS scores and CVE details reflect the record published by the CVE authority. Organizations should conduct their own risk assessments and testing before deploying patches in production environments. This summary does not constitute professional security advice tailored to your specific infrastructure or compliance requirements. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20066HIGHWordPress CP Polls 1.0.8 Persistent XSS Vulnerability
- CVE-2016-20084HIGHWordPress Appointment-Booking-Calendar Unauthenticated XSS and Privilege Escalation
- CVE-2023-33999HIGHDOM-Based XSS in WP Mail Log Plugin – Analysis & Remediation
- CVE-2023-45795HIGHXSS in Pilz PASvisu Builder Component – Patch Guidance
- CVE-2023-45796HIGHStored XSS in Pilz PASvisu & PMI Industrial Software – Remediation Guide
- CVE-2023-54351HIGHStored XSS in WordPress Sonaar Music Plugin 4.7 – Patch & Detection Guide
- CVE-2025-11262HIGHLink Whisper Free Stored XSS Vulnerability – Analysis & Patch Guidance
- CVE-2025-14773HIGHABB T-MAC Plus XSS Vulnerability – HIGH Risk Assessment