WordPress Plugin Vulnerabilities

Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode

Description

The plugin does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Abdullah Kareem (cyberkareem)
Submitter
Abdullah Kareem (cyberkareem)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 3 days ago)
Added
2026-09-10 (about 2 days ago)
Last Updated
2026-09-10 (about 2 days ago)

Other