cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpremmerce-woocommerce-wishlist premmerce-woocommerce-wishlist

Direction: ascending
Jun 06, 2024

Premmerce Wishlist for WooCommerce # 4c9caab2147a94d57962bebff673865579b6c3bf

Date
Feb 28, 2022
Research Description
Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.8 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Premmerce Wishlist for WooCommerce plugin (versions <= 1.1.7).
Affected versions
max 1.1.8.
Status
vulnerable
Nov 15, 2024

Premmerce Wishlist for WooCommerce # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.1.8.
Status
vulnerable
Nov 11, 2025

Premmerce Wishlist for WooCommerce # CVE-2025-60191

CVE, Research URL

CVE-2025-60191

Date
Nov 06, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Wishlist for WooCommerce premmerce-woocommerce-wishlist allows PHP Local File Inclusion.This issue affects Premmerce Wishlist for WooCommerce: from n/a through <= 1.1.10.
Affected versions
max 1.1.11.
Status
vulnerable
Jan 10, 2026

Premmerce Wishlist for WooCommerce # CVE-2025-13440

CVE, Research URL

CVE-2025-13440

Date
Dec 12, 2025
Research Description
The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary wishlists.
Affected versions
max 1.1.11.
Status
vulnerable
Jun 13, 2026

Premmerce Wishlist for WooCommerce # CVE-2023-33999

CVE, Research URL

CVE-2023-33999

Date
Jun 11, 2026
Research Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
Affected versions
max 1.1.10.
Status
vulnerable
Jun 16, 2026

Premmerce Wishlist for WooCommerce # 6d8910c719b2a132ec93828cd37e418b19cac960

Date
Mar 04, 2022
Research Description
Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.8 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.1.8.
Status
vulnerable

Premmerce Wishlist for WooCommerce # 6c793d19ae479c91f908f06a325c787a46fa3d8e

Date
Feb 28, 2022
Research Description
Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.8 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.7 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Premmerce Wishlist for WooCommerce plugin (versions <= 1.1.7).
Affected versions
max 1.1.8.
Status
vulnerable

Premmerce Wishlist for WooCommerce # 6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76

Date
-
Research Description
Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.2 Freemius Library &lt; 2.2.4 - Subscriber+ Arbitrary Option Update The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
Affected versions
max 1.1.2.
Status
vulnerable

Premmerce Wishlist for WooCommerce # 7e57cd4f4859826de00a8e2b09ee24fb7f2d824b

Date
Feb 25, 2019
Research Description
Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.3 Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.
Affected versions
max 1.1.3.
Status
vulnerable
Jun 25, 2026

Premmerce Wishlist for WooCommerce # CVE-2026-54849

CVE, Research URL

CVE-2026-54849

Date
-
Research Description
Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.12 CVE-2026-54849
Affected versions
max 1.1.12.
Status
vulnerable