Medium 6.4
2026-02-07< 1.3.21
Premmerce <= 1.3.20 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint
Minimum safe version
1.3.21
Update to 1.3.21 or later to address 9 fixable vulnerabilities
Premmerce <= 1.3.20 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint
CVE-2025-60241
CVE-2025-64288
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Premmerce Plugin <= 1.3.17 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-23719
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Premmerce plugin <= 1.3.15 - Sensitive Information Disclosure vulnerability
WordPress Premmerce plugin <= 1.3.15 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability