WordPress · Premmerce Permalink Manager For Woocommerce · CVE-2026-57758
**Name of the Vulnerable Software and Affected Versions**
Permalink Manager for WooCommerce versions prior to 1.0.8.3
**Description**
An unauthenticated Cross Site Request Forgery (CSRF) issue exists, which can lead to Stored Cross-Site Scripting (XSS). CSRF is a flaw that allows an attacker to trick a victim into performing actions they did not intend to take, while Stored XSS occurs when a malicious script is permanently stored on the target server and executed in the browser of users who visit the affected page.
**Recommendations**
Update Permalink Manager for WooCommerce to a version newer than 1.0.8.2.