Premmerce Wholesale Pricing for WooCommerce Security & Risk Analysis

wordpress.org/plugins/premmerce-woocommerce-wholesale-pricing

Premmerce Wholesale Pricing for WooCommerce is a plugin that allows you to add individual wholesale prices or other price types for WooCommerce produc …

500 active installs v1.1.12 PHP 5.6+ WP 4.8+ Updated Feb 19, 2026
custom-pricescustom-product-priceswholesale-priceswoocommerce-custom-priceswoocommerce-wholesale-pricing
92
A · Safe
CVEs total4
Unpatched0
Last CVENov 17, 2025
Safety Verdict

Is Premmerce Wholesale Pricing for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Premmerce Wholesale Pricing for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Nov 17, 2025Updated 1mo ago
Risk Assessment

The static analysis of Premmerce WooCommerce Wholesale Pricing v1.1.12 reveals a mixed security posture. While the plugin demonstrates good practices in key areas such as SQL query preparation (100% using prepared statements) and a low number of entry points with no apparent unprotected ones, there are significant concerns. The taint analysis shows 3 flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if they interact with sensitive operations, even though no critical or high severity issues were flagged in this specific analysis. The plugin's vulnerability history is a major red flag, with a significant number of past high and medium severity vulnerabilities, including SQL injection, PHP remote file inclusion, and missing authorization. The fact that the last vulnerability was in 2025-11-17, and is described as 'unpatched' if that date were in the past, strongly suggests a pattern of introducing security flaws that require patching.

Despite the current static analysis not flagging critical or high severity taint flows, the historical pattern of high-severity vulnerabilities and the presence of unsanitized paths in the taint analysis warrant caution. The plugin has a history of critical types of vulnerabilities that have been addressed in the past. The current static analysis shows 70% proper output escaping, meaning 30% of outputs are potentially unescaped, which can lead to XSS vulnerabilities. The presence of nonce checks and capability checks is positive, but the overall history suggests a need for rigorous and ongoing security testing. A balanced conclusion is that while some secure coding practices are employed, the historical vulnerability landscape and current taint analysis results indicate potential for exploitable weaknesses.

Key Concerns

  • Taint flows with unsanitized paths detected
  • 30% of outputs are not properly escaped
  • Bundled Freemius v1.0 library
  • 4 High severity vulnerabilities in history
  • 1 Medium severity vulnerability in history
Vulnerabilities
4

Premmerce Wholesale Pricing for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
3
Medium
1

4 total CVEs

CVE-2025-12411high · 7.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Premmerce Wholesale Pricing for WooCommerce <= 1.1.10 - Authenticated (Subscriber+) SQL Injection

Nov 17, 2025 Patched in 1.1.11 (100d)
CVE-2025-60192high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Premmerce Wholesale Pricing for WooCommerce <= 1.1.10 - Unauthenticated Local File Inclusion

Jul 28, 2025 Patched in 1.1.11 (213d)
CVE-2025-64285medium · 4.3Missing Authorization

Premmerce Wholesale Pricing for WooCommerce <= 1.1.10 - Missing Authorization

Apr 22, 2025 Patched in 1.1.11 (310d)

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

Feb 25, 2019 Patched in 1.1.4 (1793d)
Code Analysis
Analyzed Mar 16, 2026

Premmerce Wholesale Pricing for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
13 prepared
Unescaped Output
13
31 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

100% prepared13 total queries

Output Escaping

70% escaped44 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
add (src\Admin\Admin.php:292)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Premmerce Wholesale Pricing for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionadmin_menusrc\Admin\Admin.php:40
actionadmin_menusrc\Admin\Admin.php:41
actioninitsrc\Admin\Admin.php:43
actionadmin_post_premmerce_create_price_typesrc\Admin\Admin.php:49
actionadmin_post_premmerce_update_price_typesrc\Admin\Admin.php:50
actionadmin_post_premmerce_delete_price_typesrc\Admin\Admin.php:51
actionwoocommerce_before_order_object_savesrc\Admin\Admin.php:54
actionwoocommerce_before_order_item_line_item_htmlsrc\Admin\Admin.php:56
actionwoocommerce_product_options_general_product_datasrc\Admin\AdminProducts.php:35
actionwoocommerce_process_product_metasrc\Admin\AdminProducts.php:36
actionwoocommerce_product_after_variable_attributessrc\Admin\AdminProducts.php:38
actionwoocommerce_save_product_variationsrc\Admin\AdminProducts.php:39
filterwoocommerce_product_get_pricesrc\Frontend\Frontend.php:28
filterwoocommerce_product_get_sale_pricesrc\Frontend\Frontend.php:29
filterwoocommerce_product_get_regular_pricesrc\Frontend\Frontend.php:30
filterwoocommerce_product_variation_get_pricesrc\Frontend\Frontend.php:33
filterwoocommerce_product_variation_get_sale_pricesrc\Frontend\Frontend.php:34
filterwoocommerce_product_variation_get_regular_pricesrc\Frontend\Frontend.php:35
filterwoocommerce_variation_prices_pricesrc\Frontend\Frontend.php:38
filterwoocommerce_variation_prices_sale_pricesrc\Frontend\Frontend.php:39
filterwoocommerce_variation_prices_regular_pricesrc\Frontend\Frontend.php:40
filterwoocommerce_get_variation_prices_hashsrc\Frontend\Frontend.php:42
actioninitsrc\PriceTypesPlugin.php:60
actionadmin_initsrc\PriceTypesPlugin.php:61
filterhide_account_tabsviews\admin\tabs\account.php:8
Maintenance & Trust

Premmerce Wholesale Pricing for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version5.6
Downloads20K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Premmerce Wholesale Pricing for WooCommerce Developer Profile

Premmerce

14 plugins · 60K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
416 days
View full developer profile
Detection Fingerprints

How We Detect Premmerce Wholesale Pricing for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/premmerce-woocommerce-wholesale-pricing/assets/css/admin.css/wp-content/plugins/premmerce-woocommerce-wholesale-pricing/assets/css/price-types.css/wp-content/plugins/premmerce-woocommerce-wholesale-pricing/assets/js/admin-price-types.js/wp-content/plugins/premmerce-woocommerce-wholesale-pricing/assets/js/price-types.js
Script Paths
/wp-content/plugins/premmerce-woocommerce-wholesale-pricing/assets/js/admin-price-types.js/wp-content/plugins/premmerce-woocommerce-wholesale-pricing/assets/js/price-types.js
Version Parameters
premmerce-woocommerce-wholesale-pricing/assets/css/admin.css?ver=premmerce-woocommerce-wholesale-pricing/assets/css/price-types.css?ver=premmerce-woocommerce-wholesale-pricing/assets/js/admin-price-types.js?ver=premmerce-woocommerce-wholesale-pricing/assets/js/price-types.js?ver=

HTML / DOM Fingerprints

CSS Classes
premmerce-price-types-tablepremmerce-price-type-formpremmerce-price-types-form
HTML Comments
Premmerce Wholesale Pricing for WooCommerce
Data Attributes
data-nonce-deletedata-nonce-updatedata-price-type-id
JS Globals
premmerce_price_types_admin_params
FAQ

Frequently Asked Questions about Premmerce Wholesale Pricing for WooCommerce