CyberRota Analysis
AI-GeneratedThe Product Feed Manager for WooCommerce plugin in WordPress versions prior to 7.6.1 is vulnerable to SQL injection due to inadequate sanitization and escaping of custom filter rules. This flaw allows users with Contributor roles and higher to manipulate SQL queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.
Original NVD Description
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.