← WordPress Vulnerabilities
WordPress security by component

Premmerce Wishlist for WooCommerce

Premmerce Wishlist for WooCommerce is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 25, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: premmerce-woocommerce-wishlist

CVE-2026-54849: Premmerce Wishlist for WooCommerce: SQL injection

Premmerce Wishlist for WooCommerce is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.1.11.

PublishedJun 25, 2026
Known safe version1.1.12
Safe version
Jun 25, 2026 CVE-2026-54849
Premmerce Wishlist for WooCommerce: SQL injection
Premmerce Wishlist for WooCommerce is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.1.11.
1.1.12
CVE9.3
NVDPending
Dec 12, 2025 CVE-2025-13440
Premmerce Wishlist for WooCommerce: A security weakness
Premmerce Wishlist for WooCommerce is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 06, 2025 CVE-2025-60191
Premmerce Wishlist for WooCommerce: Filesystem traversal
Premmerce Wishlist for WooCommerce is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending