The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
CVE-2026-15258
NONE
EPSS 0.16%
Updated Jul 31, 2026
Unknown
unknown:product feed manager for woocommerce
CVE Details
CVE ID
CVE-2026-15258
Published Date
Jul 31, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.16%
Likelihood of exploitation in next 30 days
Percentile:
5.3th percentile (higher than 5.3% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory