# CVE-2024-27971

## Summary

- **CVE ID:** CVE-2024-27971
- **Severity:** HIGH
- **CVSS Score:** 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-22, CWE-98
- **Published:** May 17, 2024
- **Last Modified:** May 11, 2026

## Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through 2.3.10.

## Affected Products

- Premmerce — Premmerce Permalink Manager for WooCommerce (n/a)
- Premmerce — Premmerce Permalink Manager for WooCommerce (0)

## References

- [CNA](https://patchstack.com/database/vulnerability/woo-permalink-manager/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-10-local-file-inclusion-vulnerability?_s_id=cve)
- [CNA](https://patchstack.com/database/Wordpress/Plugin/woo-permalink-manager/vulnerability/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-10-local-file-inclusion-vulnerability?_s_id=cve)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.46%
- **EPSS Percentile:** 72.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._