Description
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Update plugin
AI Analysis

Impact

Unauthenticated Cross Site Scripting (XSS) exists in Premmerce Wishlist for WooCommerce plugin versions up to and including 1.1.13. The flaw allows an attacker to inject JavaScript into the plugin’s output, potentially enabling malicious scripts to run in the browsers of any user who views a wishlist page. This could lead to session hijacking, defacement, or the compromise of sensitive data through standard XSS attack vectors. The vulnerability is classified as CWE‑79.

Affected Systems

The flaw affects all installations of the Premmerce Wishlist for WooCommerce plugin with versions 1.1.13 or older. Any WordPress site that has not upgraded to version 1.1.15 or later is potentially exposed. The vulnerability resides in the plugin’s wishlist handling code and does not rely on a specific WordPress role or other third‑party components.

Risk and Exploitability

The CVSS v3 score of 7.1 reflects a high risk to confidentiality, integrity, and availability of affected sites. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation yet. Based on the description, the likely attack vector is a web request that includes a malicious payload in a wishlist parameter; the issue is unauthenticated, meaning any visitor can craft and submit the payload.

Generated by OpenCVE AI on October 1, 2026 at 15:57 UTC.

Remediation

Vendor Solution

Update the WordPress Premmerce Wishlist for WooCommerce plugin to the latest available version (at least 1.1.15).


OpenCVE Recommended Actions

  • Update the Premmerce Wishlist for WooCommerce plugin to version 1.1.15 or later.
  • Remove or disable any custom or third‑party scripts that add JavaScript to the wishlist pages to eliminate potential leverage points.
  • Scan the WordPress database for any stored XSS payloads within the wishlist content and cleanse them.
  • Implement a Content Security Policy header that forbids inline scripts to reduce the impact of future XSS vulnerabilities.

Generated by OpenCVE AI on October 1, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Title WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:22:50.151Z

Reserved: 2026-09-24T10:23:19.164Z

Link: CVE-2026-97268

cve-icon Vulnrichment

Updated: 2026-10-01T15:22:45.739Z

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:37.963

Modified: 2026-10-01T16:18:09.043

Link: CVE-2026-97268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')