Impact
Unauthenticated Cross Site Scripting (XSS) exists in Premmerce Wishlist for WooCommerce plugin versions up to and including 1.1.13. The flaw allows an attacker to inject JavaScript into the plugin’s output, potentially enabling malicious scripts to run in the browsers of any user who views a wishlist page. This could lead to session hijacking, defacement, or the compromise of sensitive data through standard XSS attack vectors. The vulnerability is classified as CWE‑79.
Affected Systems
The flaw affects all installations of the Premmerce Wishlist for WooCommerce plugin with versions 1.1.13 or older. Any WordPress site that has not upgraded to version 1.1.15 or later is potentially exposed. The vulnerability resides in the plugin’s wishlist handling code and does not rely on a specific WordPress role or other third‑party components.
Risk and Exploitability
The CVSS v3 score of 7.1 reflects a high risk to confidentiality, integrity, and availability of affected sites. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation yet. Based on the description, the likely attack vector is a web request that includes a malicious payload in a wishlist parameter; the issue is unauthenticated, meaning any visitor can craft and submit the payload.
OpenCVE Enrichment