WordPress Plugin Vulnerabilities
Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode
Description
The plugin does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Abdullah Kareem (cyberkareem)
Submitter
Abdullah Kareem (cyberkareem)
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-10 (about 3 days ago)
Added
2026-09-10 (about 2 days ago)
Last Updated
2026-09-10 (about 2 days ago)