Sceawere
Vulnerability Detail
CVE-2026-97272UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Premmerce Permalink Manager XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Premmerce
- Product
- Premmerce Permalink Manager for WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:38.167Z",
"pubdate": "2026-09-30T13:17:38.167Z",
"executiveSummary": "The Premmerce Permalink Manager for WooCommerce plugin, specifically in versions 2.3.13 and below, contains an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw enables remote, unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session. By tricking an authenticated user—such as an administrator—into interacting with a specially crafted URL, an attacker can bypass security restrictions. The impact of this vulnerability is significant, as it facilitates session hijacking, unauthorized actions performed on behalf of the administrator, and the potential for full site compromise or data exfiltration. Because this vulnerability does not require authentication, it poses a high risk to WordPress installations utilizing this plugin. The flaw exists due to improper neutralization of user-supplied input before reflecting it back to the end user in the administrative interface.",
"technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw located within the Premmerce Permalink Manager for WooCommerce plugin. The root cause of this vulnerability is the failure of the application to properly sanitize or escape input parameters passed through HTTP GET requests before rendering them back into the browser's Document Object Model (DOM) during administrative dashboard operations. In versions 2.3.13 and earlier, specific input fields or URL parameters processed by the plugin are directly echoed to the administrative screen without sufficient input validation or output encoding (e.g., using WordPress functions like esc_html() or esc_attr()).\nThe attack flow begins when an attacker crafts a malicious URL containing an XSS payload—typically encoded JavaScript—within a vulnerable parameter recognized by the plugin. The attacker then lures a high-privileged user (e.g., a site administrator who is currently authenticated) to click the link or visit the page. When the victim navigates to the URL, the web server processes the request and embeds the malicious payload directly into the HTML response generated by the plugin's administration page.\nOnce the victim's browser receives the malicious HTML, it executes the embedded JavaScript under the victim's session. Since the victim is an administrator, the script operates with elevated privileges, allowing it to perform unauthorized actions such as creating new administrative accounts, modifying plugin settings, redirecting traffic, or exfiltrating sensitive information like session cookies and nonces. The lack of authentication required to initiate this attack makes it particularly dangerous, as it essentially removes the barrier to entry for unauthorized actors aiming to compromise a site's integrity.\nThe vulnerability is primarily triggered through the reflection of input into the administrative dashboard, meaning the attack requires the victim to be authenticated while the attacker does not. This is a common pattern in WordPress plugin vulnerabilities where backend administrative interfaces fail to treat user-controlled URL parameters as untrusted. The successful exploitation of this vulnerability confirms that the plugin's request handling logic is susceptible to script injection, thereby violating the principle of secure input handling and output sanitization required to prevent injection attacks."
}