Junglewise Threat Intelligence

CVE-2026-54849: Premmerce Wishlist for WooCommerce SQL injection

CVE-2026-54849 · Severity: critical · CVSS 9.3 · Published 2026-06-25

Executive brief

A vulnerability exists in the Premmerce Wishlist plugin for WooCommerce, which allows customers to save products for later purchase. An attacker can exploit this flaw to interact directly with the website's database without needing to log in. This could lead to the theft of sensitive customer information or unauthorized access to store data, potentially disrupting business operations and damaging the site's reputation.

Technical details

The Premmerce Wishlist for WooCommerce plugin (versions 1.1.11 and below) is vulnerable to an unauthenticated SQL injection. The flaw stems from improper neutralization of special elements used in an SQL command (CWE-89), allowing a remote attacker to send specially crafted requests to the server. Because the vulnerability does not require authentication (PR:N) and has a low attack complexity (AC:L), an attacker can execute arbitrary SQL queries to extract sensitive data from the database. The issue is resolved in version 1.1.12.

Affected products

  • Premmerce Premmerce Wishlist for WooCommerce <= 1.1.11

Timeline

  • 2026-04-29: other: Vulnerability reported by researcher hhhai
  • 2026-06-18: advisory: Patchstack advisory published
  • 2026-06-25: disclosed: NVD publication date

References