CVE-2026-0555
- EPSS 0.01%
- Veröffentlicht 07.02.2026 08:26:38
- Zuletzt bearbeitet 09.02.2026 16:08:35
The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1.3.20. This is due to missing capability checks and insufficient input sanitizatio...
CVE-2025-60241
- EPSS 0.14%
- Veröffentlicht 06.11.2025 15:55:13
- Zuletzt bearbeitet 20.01.2026 15:17:36
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce premmerce allows PHP Local File Inclusion.This issue affects Premmerce: from n/a through <= 1.3.19.
CVE-2025-64288
- EPSS 0.03%
- Veröffentlicht 29.10.2025 08:38:14
- Zuletzt bearbeitet 20.01.2026 15:18:53
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This issue affects Premmerce: from n/a through <= 1.3.19.
CVE-2023-23719
- EPSS 0.04%
- Veröffentlicht 17.07.2023 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:43
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce plugin <= 1.3.17 versions.