Cross Site Scripting Vulnerability in Premmerce Wishlist for WooCommerce Plugin
CVE-2026-97273
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-97273?
The Premmerce Wishlist for WooCommerce plugin versions 1.1.13 and below have a vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript code via crafted payloads. This can lead to various malicious activities, including session hijacking or redirecting users to harmful sites. Website administrators should urgently update to the latest version to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Premmerce Wishlist for WooCommerce <= 1.1.13