Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesProduct Feed Manager for WooCommerce

Product Feed Manager for WooCommerce vulnerabilities

Product Feed Manager for WooCommerce has 3 known vulnerabilities in this database. The most recent published record is dated 22 Sep 2026.

Known vulnerabilities
3
Active installs
90,000+
Latest version
8.0.30
Last updated
30 Sep 2026
Most recent
22 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Remote code execution
CVE-2026-15095
Medium 4.9Up to 6.6.43Fixed in a later version (latest 8.0.30)22 Sep 2026
SQL injection
CVE-2026-15258
High 8.1Before 7.6.1Fixed in 7.6.131 Jul 2026
Remote code execution
CVE-2025-12975
High 7.2Up to 6.6.11Fixed in a later version (latest 8.0.30)19 Feb 2026
Read the published descriptions
CVE-2026-15095, 22 Sep 2026
The Product Feed Manager for WooCommerce - CTX Feed - Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to delete arbitrary files on the server, which can lead to remote code execution when critical files are deleted. Exploitation requires two sequential REST API calls: first to /wp-json/ctxfeed/v1/make_feed/save_feed_config to persist the traversal payload in wp_options, then to /wp-json/ctxfeed/v1/manage_feeds/delete_feed to trigger the unlink(); deletion is further constrained to files whose extensions match the plugin's validated whitelist (csv, xml, tsv, xls, xlsx, json, txt). CVE record
CVE-2026-15258, 31 Jul 2026
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. CVE record
CVE-2025-12975, 19 Feb 2026
The CTX Feed - WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to install arbitrary plugins which can be leveraged to achieve remote code execution. CVE record

What to do if you run Product Feed Manager for WooCommerce

If you run Product Feed Manager for WooCommerce, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Product Feed Manager for WooCommerce vulnerabilities

Free. We email you when a new vulnerability is published for Product Feed Manager for WooCommerce, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support