WPIntell

Source evidence

Potential SQL Injection / Malicious Wishlist Entries

YITH WooCommerce Wishlist · support · 2026-04-01T23:14:00+00:00

complaintsentiment
highseverity
0.82relevance
0replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 26 rows with source links

15.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

22 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
blueazure000 unresolved
Hi, I’m seeing suspicious activity in my site related to the YITH Wishlist plugin. The logs show attempts to add wishlist items containing potentially malicious SQL-like input, for example: [30-Mar-2026 20:42:53 UTC] Exception caught in get_wishlist. Invalid wishlist.. Args: Array ( [0] => Vgha AND 5303 IN (SELECT (CHAR(113)+CHAR(106)+CHAR(98)+CHAR(113)+CHAR(113)+(SELECT (CASE WHEN (5303=5303) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(120)+CHAR(98)+CHAR(98)+CHAR(113)))– uZuA ) .. [30-Mar-2026 20:43:04 UTC] Exception caught in get_wishlist. Invalid wishlist.. Args: Array ( [0] => Vgha\’) ORDER BY 1– WoAa )

Comments

0 shown

No comments were stored for this source.