Impact
The Premmerce Product Search for WooCommerce plugin implements a Cross‑Site Request Forgery flaw that allows an attacker to forge requests on behalf of a logged‑in user. By tricking the user into visiting a specially crafted URL or submitting a malicious form, the attacker can trigger the plugin’s search or related endpoints without consent. This can lead to unintended data exposure or manipulation of search parameters, potentially jeopardizing confidentiality and integrity of the site’s content.
Affected Systems
This vulnerability affects the Premmerce Product Search for WooCommerce plugin versions up to and including 2.2.4. The affected product is distributed by Premmerce and commonly installed on WordPress sites that utilize WooCommerce for e‑commerce operations.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score under 1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further supporting a lower exploitation probability. Attacks would typically originate from a web browser that has an active authenticated session with the site, making the typical attack vector a user‑initiated request.
OpenCVE Enrichment