HomeWordPress vulnerabilitiesProduct Feed Manager for WooCommerce
Product Feed Manager for WooCommerce vulnerabilities
Product Feed Manager for WooCommerce has 3 known vulnerabilities in this database. The most recent published record is dated 22 Sep 2026.
- Known vulnerabilities
- 3
- Active installs
- 90,000+
- Latest version
- 8.0.30
- Last updated
- 30 Sep 2026
- Most recent
- 22 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Remote code execution CVE-2026-15095 | Medium 4.9 | Up to 6.6.43 | Fixed in a later version (latest 8.0.30) | 22 Sep 2026 |
| SQL injection CVE-2026-15258 | High 8.1 | Before 7.6.1 | Fixed in 7.6.1 | 31 Jul 2026 |
| Remote code execution CVE-2025-12975 | High 7.2 | Up to 6.6.11 | Fixed in a later version (latest 8.0.30) | 19 Feb 2026 |
Read the published descriptions
- CVE-2026-15095, 22 Sep 2026
- The Product Feed Manager for WooCommerce - CTX Feed - Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to delete arbitrary files on the server, which can lead to remote code execution when critical files are deleted. Exploitation requires two sequential REST API calls: first to /wp-json/ctxfeed/v1/make_feed/save_feed_config to persist the traversal payload in wp_options, then to /wp-json/ctxfeed/v1/manage_feeds/delete_feed to trigger the unlink(); deletion is further constrained to files whose extensions match the plugin's validated whitelist (csv, xml, tsv, xls, xlsx, json, txt). CVE record
- CVE-2026-15258, 31 Jul 2026
- The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. CVE record
- CVE-2025-12975, 19 Feb 2026
- The CTX Feed - WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to install arbitrary plugins which can be leveraged to achieve remote code execution. CVE record
What to do if you run Product Feed Manager for WooCommerce
If you run Product Feed Manager for WooCommerce, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Product Feed Manager for WooCommerce vulnerabilities
Free. We email you when a new vulnerability is published for Product Feed Manager for WooCommerce, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.