WordPress security by component
Product XML Feed Manager for WooCommerce
Product XML Feed Manager for WooCommerce (product-xml-feed-manager-for-woocommerce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 4.9.
Plugin slug:
product-xml-feed-manager-for-woocommerceLatest vulnerability
CVE-2026-87919: Product XML Feed Manager shortcode can delete arbitrary products
Product XML Feed Manager for WooCommerce before 3.1.1 lets its product shortcode call an unrestricted object method and does not check capability over the targeted product. A contributor can preview a post containing the shortcode to invoke deletion against an arbitrary WooCommerce product. The authoritative export does not identify the shortcode tag, method parameter, or product identifier field.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-87919
Product XML Feed Manager shortcode can delete arbitrary products
Product XML Feed Manager for WooCommerce before 3.1.1 lets its product shortcode call an unrestricted object method and does not check capability over the targeted product. A contributor can preview a post containing the shortcode to invoke deletion against an arbitrary WooCommerce product. The authoritative export does not identify the shortcode tag, method parameter, or product identifier field.
|
3.1.1 |
CVE4.9
NVDPending
|