Premmerce develops a suite of WooCommerce plugins and extensions focused on e-commerce functionality, including product filtering, URL redirection, and marketplace integration tools. The reported vulnerabilities concentrate on application-layer weaknesses spanning cross-site request forgery, cross-site scripting, and missing authorization checks, which are characteristic of web-facing WordPress and WooCommerce components. Current severity, exploitation status, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Premmerce over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60241HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce premmerce allows PHP Local File Inclusi | Nov 6, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-31359HIGH Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce premmerce-woocommerce-product-filter.This issue affects Premmerce Product Filter for WooCo | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-23719HIGH Cross-Site Request Forgery (CSRF) vulnerability in Premmerce plugin <= 1.3.17 versions. | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-23787HIGH Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions. | Jul 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-0555MEDIUM The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1.3.20. This | Feb 7, 2026 | 6.4 | 21 | NO | NO |
CVE-2025-64288MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This issue affects Premmerce: from n/a through <= 1.3.19. | Oct 29, 2025 | 4.3 | 18 | NO | NO |
CVE-2023-23789MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions. | May 10, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Premmerce.
Media articles that mention a CVE ID that affects a product developed by Premmerce — matched by CVE ID, not by vendor name.