VYPR

Product XML Feed Manager for WooCommerce

by WordPress

CVEs (6)

  • CVE-2025-49887CriAug 14, 2025
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Remote Code Inclusion.This issue affects Product XML Feed Manager for WooCommerce: from n/a through <= 2.9.3.

  • CVE-2026-15258HigJul 31, 2026
    risk 0.53cvss 8.1epss 0.00

    The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

  • CVE-2025-30959MedJul 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product XML Feed Manager for WooCommerce: from n/a through <=…

  • CVE-2026-15095MedSep 22, 2026
    risk 0.32cvss 4.9epss 0.01

    The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes it possible for authenticated…

  • CVE-2026-87919MedSep 12, 2026
    risk 0.32cvss 4.9epss 0.00

    The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary…

  • CVE-2026-15306MedJul 16, 2026
    risk 0.00cvss 6.1epss 0.00

    The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping.…