
CVE-2026-0555 The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1… https://www.cve.org/CVERecord?id=CVE-2026-0555
Post summary
The Premmerce WordPress plugin is vulnerable to a stored XSS flaw through its AJAX endpoint, as disclosed in CVE-2026-0555.
