Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Premmerce — Vulnerabilities & Security Advisories 24

Browse all 24 CVE security advisories affecting Premmerce. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Premmerce operates as a comprehensive e-commerce platform designed to facilitate online retail operations, offering modules for product management, order processing, and customer engagement. Security audits have identified twenty-four distinct Common Vulnerabilities and Exposures (CVEs) associated with the software, indicating a persistent history of security deficiencies. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper access controls. Additionally, instances of privilege escalation and broken authentication mechanisms have been documented, allowing unauthorized users to manipulate system functions or access sensitive data. These flaws suggest that the platform has historically struggled with secure coding practices, particularly in handling user-generated content and administrative interfaces. While no single catastrophic public breach has been widely publicized, the cumulative volume of CVEs highlights significant risks for organizations relying on Premmerce for critical business transactions without rigorous patch management and security hardening.

CVE IDTitleCVSSSeverityPublished
CVE-2026-32541 WordPress Premmerce Redirect Manager plugin <= 1.0.12 - Broken Access Control vulnerability — Premmerce Redirect ManagerCWE-862 6.5 Medium2026-03-25
CVE-2026-0555 Premmerce <= 1.3.20 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint — PremmerceCWE-79 6.4 Medium2026-02-07
CVE-2025-13369 Premmerce WooCommerce Customers Manager <= 1.1.14 - Reflected Cross-Site Scripting — Premmerce WooCommerce Customers ManagerCWE-79 6.1 Medium2026-01-07
CVE-2025-13440 Premmerce Wishlist for WooCommerce <= 1.1.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion — Premmerce Wishlist for WooCommerceCWE-862 5.3 Medium2025-12-12
CVE-2025-12783 Premmerce Brands for WooCommerce <= 1.2.13 - Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update — Premmerce Brands for WooCommerceCWE-862 4.3 Medium2025-12-12
CVE-2025-12411 Premmerce Wholesale Pricing for WooCommerce <= 1.1.10 - Authenticated (Subscriber+) SQL Injection — Premmerce Wholesale Pricing for WooCommerceCWE-89 7.1 High2025-11-18
CVE-2025-60241 WordPress Premmerce plugin <= 1.3.19 - Local File Inclusion vulnerability — PremmerceCWE-98 7.5 High2025-11-06
CVE-2025-60194 WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Local File Inclusion vulnerability — Premmerce Product Search for WooCommerceCWE-98 7.5 High2025-11-06
CVE-2025-60193 WordPress Premmerce User Roles plugin <= 1.0.13 - Local File Inclusion vulnerability — Premmerce User RolesCWE-98 7.5 High2025-11-06
CVE-2025-60192 WordPress Premmerce Wholesale Pricing for WooCommerce plugin <= 1.1.10 - Local File Inclusion vulnerability — Premmerce Wholesale Pricing for WooCommerceCWE-98 7.5 High2025-11-06
CVE-2025-60191 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.10 - Local File Inclusion vulnerability — Premmerce Wishlist for WooCommerceCWE-98 7.5 High2025-11-06
CVE-2025-64291 WordPress Premmerce User Roles plugin <= 1.0.13 - Cross Site Scripting (XSS) vulnerability — Premmerce User RolesCWE-79 5.9 Medium2025-10-29
CVE-2025-64290 WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability — Premmerce Product Search for WooCommerceCWE-352 4.3 Medium2025-10-29
CVE-2025-64289 WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.5 - Cross Site Scripting (XSS) vulnerability — Premmerce Product Search for WooCommerceCWE-79 5.9 Medium2025-10-29
CVE-2025-64288 WordPress Premmerce plugin <= 1.3.19 - Cross Site Request Forgery (CSRF) vulnerability — PremmerceCWE-352 4.3 Medium2025-10-29
CVE-2025-64285 WordPress Premmerce Wholesale Pricing for WooCommerce plugin <= 1.1.10 - Broken Access Control vulnerability — Premmerce Wholesale Pricing for WooCommerceCWE-862 5.4 Medium2025-10-29
CVE-2025-62890 WordPress Premmerce Brands for WooCommerce plugin <= 1.2.13 - Cross Site Request Forgery (CSRF) vulnerability — Premmerce Brands for WooCommerceCWE-352 4.3 Medium2025-10-27
CVE-2025-62883 WordPress Premmerce User Roles plugin <= 1.0.13 - Broken Access Control vulnerability — Premmerce User RolesCWE-862 4.3 Medium2025-10-27
CVE-2023-41130 WordPress Premmerce User Roles plugin <= 1.0.12 - Broken Access Control vulnerability — Premmerce User RolesCWE-862 8.1 High2024-12-13
CVE-2024-31359 WordPress Premmerce Product Filter for WooCommerce plugin <= 3.7.2 - Broken Access Control vulnerability — Premmerce Product Filter for WooCommerceCWE-862 4.3 Medium2024-06-09
CVE-2024-27971 WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability — Premmerce Permalink Manager for WooCommerceCWE-98 8.3 High2024-05-17
CVE-2023-23719 WordPress Premmerce Plugin <= 1.3.17 is vulnerable to Cross Site Request Forgery (CSRF) — PremmerceCWE-352 5.4 Medium2023-07-17
CVE-2023-23787 WordPress Premmerce Redirect Manager Plugin <= 1.0.9 is vulnerable to Cross Site Request Forgery (CSRF) — Premmerce Redirect ManagerCWE-352 4.3 Medium2023-07-10
CVE-2023-23789 WordPress Premmerce Redirect Manager Plugin <= 1.0.9 is vulnerable to Cross Site Scripting (XSS) — Premmerce Redirect ManagerCWE-79 5.9 Medium2023-05-10

This page lists every published CVE security advisory associated with Premmerce. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.