Premmerce User Roles
Premmerce User Roles has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 6 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 8.3 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 3 disclosures.
The most common weakness is Missing Authorization, behind 3 of the records (50%). Other recurring categories include Cross-Site Scripting, PHP Remote File Inclusion.
Every one of the 6 issues recorded for Premmerce User Roles has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, one record each. Premmerce User Roles is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2023-41130Premmerce User Roles <= 1.0.12 - Missing Authorization via role management functions
Read the full analysisVulnerability Records

Premmerce User Roles
Author
Premmerce
This plugin has been developed for creating user roles from the WordPress admin area and assigning the arbitrary access rights to them. Full documentation is available here: Premmerce User Roles Major features of “Premmerce User Roles” adding user roles with the features needed viewing the features of the standard WordPress roles deleting the created user roles editing the created user roles granting the arbitrary access rights to the user roles inheriting the features of the existing roles Demo You can create your personal demo store and test this plugin together with Premmerce Premium and all other Premmerce plugins and themes developed by our team here: Premmerce WooCommerce Demo . Compatibility with the other Plugins WooCommerce WooCommerce Multilingual
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C