Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-0555 2 Premmerce, Wordpress 2 Premmerce, Wordpress 2026-02-11 6.4 Medium
The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1.3.20. This is due to missing capability checks and insufficient input sanitization and output escaping on the `state` parameter. This makes it possible for authenticated attackers, with subscriber level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (the Premmerce Wizard admin page).
CVE-2023-23789 1 Premmerce 1 Premmerce Redirect Manager 2025-01-09 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.
CVE-2024-31359 1 Premmerce 1 Premmerce Product Filter For Woocommerce 2024-11-21 4.3 Medium
Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce.This issue affects Premmerce Product Filter for WooCommerce: from n/a through 3.7.2.
CVE-2023-23719 1 Premmerce 1 Premmerce 2024-11-21 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce plugin <= 1.3.17 versions.