← WordPress Vulnerabilities
WordPress security by component

WP eBay Product Feeds

WP eBay Product Feeds is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Dec 09, 2025; the highest CVE/CNA score is 6.1.

Plugin slug: ebay-feeds-for-wordpress

CVE-2025-67557: WP eBay Product Feeds: Cross-site scripting

WP eBay Product Feeds is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedDec 09, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 09, 2025 CVE-2025-67557
WP eBay Product Feeds: Cross-site scripting
WP eBay Product Feeds is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Sep 09, 2025 CVE-2025-58977
WP eBay Product Feeds: Server-side request forgery
WP eBay Product Feeds is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVDPending
Mar 23, 2023 CVE-2023-23722
Ebay Feeds For Wordpress: Cross-site scripting
Ebay Feeds For Wordpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Dec 27, 2019 CVE-2014-4525
Ebay Feeds for: Cross-site scripting
Ebay Feeds for is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1