Product Feed Manager for WooCommerce <= 8.0.31 - Authenticated (Shop Manager+) Arbitrary Options Deletion

Medium 6.5 CWE-639Fixed in 8.0.32
ID
WPSEC-2026-0635
Plugin
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels (webappick-product-feed-for-woocommerce)
Affected
from 8.0.0 before 8.0.32
Remediation
Update to 8.0.32 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Product Feed Manager for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary options deletion in versions 8.0.0 up to, and including, 8.0.31. The feed REST endpoints treat a numeric feed ID as a wp_options row ID and do not check that the row belongs to a feed. This makes it possible for authenticated attackers with Shop Manager-level access and above to delete arbitrary options from the WordPress options table, which can make the site unusable.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0