Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
Affected products
Unknown · Product Feed Manager For WooCommerce