{
 "id": "WPSEC-2026-0707",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0707/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0707/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0707/index.md",
 "title": "Product Feed Manager for WooCommerce <= 8.0.32 - Unauthenticated Sensitive Information Exposure via Log Files",
 "description": "The Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.0.32 due to feed and system log files being stored in a predictable, publicly accessible location (wp-content/uploads/woo-feed/logs/) that is protected only by .htaccess rules. This makes it possible for unauthenticated attackers to download the plugin's log files, and any data they contain, by requesting them directly on servers that ignore .htaccess files, such as Nginx.",
 "plugin": {
  "slug": "webappick-product-feed-for-woocommerce",
  "name": "Product Feed Manager for WooCommerce",
  "full_name": "Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels",
  "wordpress_org": "https://wordpress.org/plugins/webappick-product-feed-for-woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/webappick-product-feed-for-woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/webappick-product-feed-for-woocommerce"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-552"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "8.0.33",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 8.0.33"
  ]
 },
 "introduced_in": null,
 "fixed_in": "8.0.33",
 "remediation": "Update to 8.0.33 or later.",
 "fix_released": "2026-10-08T13:55:07+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:25.952036+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0707/",
  "https://plugins.svn.wordpress.org/webappick-product-feed-for-woocommerce/tags/8.0.33/",
  "https://wordpress.org/plugins/webappick-product-feed-for-woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/webappick-product-feed-for-woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}