CVE-2026-15258 PUBLISHED

Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter

Assigner: WPScan
Reserved: 09.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

Product Status

Vendor Unknown
Product Product Feed Manager For WooCommerce
Versions Default: unaffected
  • affected from 0 to 7.6.1 (excl.)

Credits

  • Md Amin Ullah Sheikh finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE