The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | |
| Title | Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-31T06:00:09.816Z
Reserved: 2026-07-09T13:06:34.857Z
Link: CVE-2026-15258
No data.
No data.
No data.
OpenCVE Enrichment
No data.