{
 "id": "WPSEC-2026-0633",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0633/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0633/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0633/index.md",
 "title": "Product Feed Manager for WooCommerce <= 8.0.31 - Authenticated (Shop Manager+) Sensitive Information Exposure via WP Options",
 "description": "The Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.0.31 via the WP Options feature. The plugin lets any user with the manage_woocommerce capability add any option name to its WP Options list and returns the current value of every listed option. This makes it possible for authenticated attackers with Shop Manager-level access and above to read arbitrary values from the WordPress options table, including passwords, API keys and other secrets that WordPress core and other plugins store there.",
 "plugin": {
  "slug": "webappick-product-feed-for-woocommerce",
  "name": "Product Feed Manager for WooCommerce",
  "full_name": "Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels",
  "wordpress_org": "https://wordpress.org/plugins/webappick-product-feed-for-woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/webappick-product-feed-for-woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/webappick-product-feed-for-woocommerce"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.9,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "8.0.32",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 8.0.32"
  ]
 },
 "introduced_in": null,
 "fixed_in": "8.0.32",
 "remediation": "Update to 8.0.32 or later.",
 "fix_released": "2026-10-07T09:41:10+00:00",
 "published": "2026-10-08T09:45:16+00:00",
 "updated": "2026-10-07T12:20:06.261851+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0633/",
  "https://plugins.svn.wordpress.org/webappick-product-feed-for-woocommerce/tags/8.0.32/",
  "https://wordpress.org/plugins/webappick-product-feed-for-woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/webappick-product-feed-for-woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}