Vulnerabilities and security researches forpremmerce-woocommerce-wishlist premmerce-woocommerce-wishlist
Direction: ascendingJun 06, 2024
Premmerce Wishlist for WooCommerce # 4c9caab2147a94d57962bebff673865579b6c3bf
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.8 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Premmerce Wishlist for WooCommerce plugin (versions <= 1.1.7).
- Affected versions
-
max 1.1.8.
- Status
-
vulnerable
Nov 15, 2024
Premmerce Wishlist for WooCommerce # CVE-2022-4974
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.1.8.
- Status
-
vulnerable
Nov 11, 2025
Premmerce Wishlist for WooCommerce # CVE-2025-60191
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 06, 2025
- Research Description
- Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Wishlist for WooCommerce premmerce-woocommerce-wishlist allows PHP Local File Inclusion.This issue affects Premmerce Wishlist for WooCommerce: from n/a through <= 1.1.10.
- Affected versions
-
max 1.1.11.
- Status
-
vulnerable
Jan 10, 2026
Premmerce Wishlist for WooCommerce # CVE-2025-13440
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 12, 2025
- Research Description
- The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary wishlists.
- Affected versions
-
max 1.1.11.
- Status
-
vulnerable
Jun 13, 2026
Premmerce Wishlist for WooCommerce # CVE-2023-33999
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 11, 2026
- Research Description
- Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
- Affected versions
-
max 1.1.10.
- Status
-
vulnerable
Jun 16, 2026
Premmerce Wishlist for WooCommerce # 6d8910c719b2a132ec93828cd37e418b19cac960
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 04, 2022
- Research Description
- Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.8 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.1.8.
- Status
-
vulnerable
Premmerce Wishlist for WooCommerce # 6c793d19ae479c91f908f06a325c787a46fa3d8e
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.8 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.7 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Premmerce Wishlist for WooCommerce plugin (versions <= 1.1.7).
- Affected versions
-
max 1.1.8.
- Status
-
vulnerable
Premmerce Wishlist for WooCommerce # 6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.2 Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
- Affected versions
-
max 1.1.2.
- Status
-
vulnerable
Premmerce Wishlist for WooCommerce # 7e57cd4f4859826de00a8e2b09ee24fb7f2d824b
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 25, 2019
- Research Description
- Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.3 Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.
- Affected versions
-
max 1.1.3.
- Status
-
vulnerable
Jun 25, 2026
Premmerce Wishlist for WooCommerce # CVE-2026-54849
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] < 1.1.12 CVE-2026-54849
- Affected versions
-
max 1.1.12.
- Status
-
vulnerable