← WordPress Vulnerabilities
WordPress security by component

Product XML Feed Manager for WooCommerce

Product XML Feed Manager for WooCommerce (product-xml-feed-manager-for-woocommerce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 4.9.

Plugin slug: product-xml-feed-manager-for-woocommerce

CVE-2026-87919: Product XML Feed Manager shortcode can delete arbitrary products

Product XML Feed Manager for WooCommerce before 3.1.1 lets its product shortcode call an unrestricted object method and does not check capability over the targeted product. A contributor can preview a post containing the shortcode to invoke deletion against an arbitrary WooCommerce product. The authoritative export does not identify the shortcode tag, method parameter, or product identifier field.

PublishedSep 12, 2026
Known safe version3.1.1
Published vulnerabilities for product-xml-feed-manager-for-woocommerce
Safe version
Sep 12, 2026 CVE-2026-87919
Product XML Feed Manager shortcode can delete arbitrary products
Product XML Feed Manager for WooCommerce before 3.1.1 lets its product shortcode call an unrestricted object method and does not check capability over the targeted product. A contributor can preview a post containing the shortcode to invoke deletion against an arbitrary WooCommerce product. The authoritative export does not identify the shortcode tag, method parameter, or product identifier field.
3.1.1
CVE4.9
NVDPending