EDD Product Catalog Feed by PixelYourSite <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter
highThe EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attacker...
- CVSS:
- 7.1 (Wordfence)
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.3
- Disclosed:
- Sep 7, 2026