PatchSiren

Product Feed Manager For WooCommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Product Feed Manager For WooCommerce CVE published 2026-07-31

CVE-2026-15258

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 is vulnerable to SQL injection attacks due to improper sanitization and escaping of product-feed custom filter rules. This vulnerability allows users with the Contributor role and above to perform SQL injection attacks. Administrators of WordPress sites using this plugin should be aware of the potential risks and take necessary precaut [truncated]