CVE-2026-27329General

LOWCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-07); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Active Exploitation · 2026-05-08: 1Technical Details · 2026-05-07: 105-0705-08
Signal classification2 categories
General
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-072
General2
2026-05-081
Active Exploitation1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting YITH WooCommerce Wishlist Plugin (CVE-2026-27329) https://vuldb.com/vuln/361813/cti

    Post summary

    The post flags observed elevated activity targeting YITH WooCommerce Wishlist plugin (CVE‑2026‑27329), suggesting active exploitation is occurring, though specific technical or PoC details are not disclosed.

    0000055
    2.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27329 Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Leve… https://www.cve.org/CVERecord?id=CVE-2026-27329

    Post summary

    The post references CVE‑2026‑27329, noting an authorization bypass due to a user‑controlled key in YITH WooCommerce Wishlist, but offers no PoC, exploit detail, patch, or evidence of active exploitation.

    0000079
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27329 Authorization Bypass Through User-Controlled Key in YITH WooCommerce Wishlist 4.12.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27329

    Post summary

    The text references CVE‑2026‑27329 and provides a link to a vulnerability summary but offers no concrete details on exploits, patches, or technical specifics.

    0000034
    4.0K followersView on X

Explore more