Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce
CVE-2026-54849
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 June 2026
What is CVE-2026-54849?
An unauthenticated SQL injection vulnerability in the Premmerce Wishlist for WooCommerce plugin allows attackers to execute arbitrary SQL commands. This flaw affects versions up to 1.1.11 and poses significant risks as it can potentially expose sensitive data and compromise the integrity of the database. Users of the plugin should take immediate action to update to a patched version to mitigate this security threat. Regular security reviews and plugin updates are essential for maintaining WordPress site integrity.
Affected Version(s)
Premmerce Wishlist for WooCommerce <= 1.1.11