high · CVSS v3 7.1
CVE-2026-97273
CVE-2026-97273 is an unauthenticated cross-site scripting vulnerability in the Premmerce Wishlist for WooCommerce plugin for WordPress/WooCo
Overview
CVE-2026-97273 is an unauthenticated cross-site scripting vulnerability in the Premmerce Wishlist for WooCommerce plugin for WordPress/WooCommerce sites. It matters because malicious script injection could affect users interacting with affected store pages. Defenders should prioritize patching or compensating controls for exposed stores.
Description
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Impact
Confidentiality and integrity can be affected if malicious script executes in a visitor's browser, potentially exposing session data or altering page content. Availability is less directly impacted, but defacement or disruptive scripts could degrade user trust and operations. Primarily impacts WooCommerce store operators, site administrators, and customers using affected plugin versions. Unauthenticated exposure increases risk for public-facing stores.
Remediation
Update Premmerce Wishlist for WooCommerce to a vendor-released version newer than 1.1.13 as soon as available. If no patched version exists, disable or remove the plugin from production stores and review recent plugin changes. Enforce strict output encoding, content security policy, and WAF rules for XSS patterns on affected endpoints. Monitor web server and application logs for anomalous script injection attempts and validate plugin integrity after updates.
Risk context
The reported CVSS v3 score is 7.1 (High), indicating a significant risk for public-facing WooCommerce sites. EPSS data is not provided, so urgency should be driven by exposure, plugin usage, and availability of a fix. Treat as high priority for internet-facing stores, especially if the plugin is enabled and unauthenticated access is possible.
Affected products
- Premmerce Wishlist for WooCommerce <= 1.1.13
- WordPress
- WooCommerce
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.1
- CVSS v4
- —
- EPSS
- —