Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.5.
Published: 2025-10-29
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of user input during web page generation. An attacker can embed malicious JavaScript that is stored by the Premmerce Product Search for WooCommerce plugin and subsequently executed whenever a user views a page that renders the stored content, enabling the attacker to hijack sessions, deface a site, or steal credentials.

Affected Systems

WordPress sites that have installed any version of the Premmerce Product Search for WooCommerce plugin from the earliest release up to and including version 2.2.5 are impacted. The issue affects all users who can input data that the plugin processes and stores without proper escaping.

Risk and Exploitability

The CVSS score of 5.9 classifies the risk as moderate, indicating a potential for moderate impact if an attacker succeeds. The EPSS score of less than 1% suggests that the probability of exploitation is low in the current threat landscape, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to exploit the web application interface to store malicious payloads, making the attack vector a web‑based one; however, once the payload is stored it is executed in any visitor’s browser without authentication.

Generated by OpenCVE AI on April 29, 2026 at 12:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Premmerce Product Search for WooCommerce plugin to a version newer than 2.2.5 or install any vendor‑supplied patch that addresses the stored XSS flaw.
  • If an upgrade is not immediately possible, disable the plugin or remove the functionality that allows user‑generated content until a fix is applied.
  • Implement input validation and output encoding for any custom fields or content that the plugin processes, ensuring that all characters are properly escaped before storage or rendering.

Generated by OpenCVE AI on April 29, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.5.
Title WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Scripting (XSS) vulnerability WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.5 - Cross Site Scripting (XSS) vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Premmerce
Premmerce premmerce
Premmerce product Search For Woocommerce
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Premmerce
Premmerce premmerce
Premmerce product Search For Woocommerce
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Wed, 29 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4.
Title WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Premmerce Premmerce Product Search For Woocommerce
Woocommerce Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:29:51.135Z

Reserved: 2025-10-29T03:29:08.850Z

Link: CVE-2025-64289

cve-icon Vulnrichment

Updated: 2025-10-29T14:01:23.568Z

cve-icon NVD

Status : Deferred

Published: 2025-10-29T09:15:46.760

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:45:11Z

Weaknesses