CVE-2026-15258

NONE EPSS 0.16%
Updated Jul 31, 2026
Unknown
Parameter Value
Affected Versions before 7.6.1
Type CWE-89 SQL Injection
Vendor Unknown
Public PoC No

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

Weakness Type (CWE)

Vulnerable Products

unknown:product feed manager for woocommerce