The Premmerce plugin for WordPress is vulnerable to...
Moderate severity
Unreviewed
Published
Feb 7, 2026
to the GitHub Advisory Database
•
Updated Feb 7, 2026
Description
Published by the National Vulnerability Database
Feb 7, 2026
Published to the GitHub Advisory Database
Feb 7, 2026
Last updated
Feb 7, 2026
The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1.3.20. This is due to missing capability checks and insufficient input sanitization and output escaping on the
stateparameter. This makes it possible for authenticated attackers, with subscriber level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (the Premmerce Wizard admin page).References