plugin

Invelity Products Feeds Vulnerabilities

2 known security issues reported for the Invelity Products Feeds WordPress plugin. Most recent disclosed Mar 23, 2026.

2 high

Running Invelity Products Feeds on your site? Check whether your installed version is affected.

Scan your site free

Invelity Product Feeds - Cross-Site Request Forgery to Arbitrary File Deletion vulnerability

high

Cross-Site Request Forgery to Arbitrary File Deletion vulnerability

CVSS:
8.1
Affected:
up to 1.2.6
Fix:
No patched version reported
Disclosed:
Mar 23, 2026

Invelity Products Feeds <= 1.2.6 - Cross-Site Request Forgery to Arbitrary File Deletion

high

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createManageFeedPage' function. This makes it possible for authenticated administrator-level attackers to de...

CVSS:
8.1
Affected:
up to 1.2.6
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2025-14037 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database