SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15258

HIGH · CVSS 8.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The Product Feed Manager for WooCommerce plugin in WordPress versions prior to 7.6.1 is vulnerable to SQL injection due to inadequate sanitization and escaping of custom filter rules. This flaw allows users with Contributor roles and higher to manipulate SQL queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-15258
Severity
HIGH
CVSS
8.1
EPSS
0.21%
WordPress

Original NVD Description

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.