plugin

Webappick Product Feed For Woocommerce Vulnerabilities

7 known security issues reported for the Webappick Product Feed For Woocommerce WordPress plugin. Most recent disclosed Aug 14, 2026.

3 high 4 medium

Running Webappick Product Feed For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels <= 6.6.46 - Authenticated (Shop Manager+) Arbitrary File Downloaf

medium

The Product Feed Manager for WooCommerce – CTXFeed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.6.46. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to read the contents of arbitrary...

CVSS:
4.9
Affected:
up to 6.6.46
Fix:
No patched version reported
Disclosed:
Aug 14, 2026

CVE-2026-73383 on NVD →

Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels <= 6.6.42 - Authenticated (Shop Manager+) Remote Code Execution

high

The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.6.42. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to execute code on the ser...

CVSS:
7.2
Affected:
up to 6.6.42
Fixed in:
6.6.43
Disclosed:
Aug 4, 2026

CVE-2026-66709 on NVD →

Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels <= 6.6.26 - Authenticated (Shop Manager+) PHP Object Injection

medium

The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.6.26 via deserialization of untrusted input. This makes it possible for authenticated attackers, with shop manager-level access and...

CVSS:
6.6
Affected:
up to 6.6.26
Fixed in:
6.6.27
Disclosed:
Apr 7, 2026

CVE-2026-39434 on NVD →

CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation

high

The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop Mana...

CVSS:
7.2
Affected:
up to 6.6.11
Fixed in:
6.6.12
Disclosed:
Feb 18, 2026

CVE-2025-12975 on NVD →

CTX Feed <= 6.6.18 - Missing Authorization

medium

The CTX Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.6.18. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.6.18
Fixed in:
6.6.19
Disclosed:
Jan 4, 2026

CVE-2026-22461 on NVD →

CTX Feed <= 6.5.6 - Authenticated (Shop Manager+) Arbitrary Options Update

high

The CTX Feed – WooCommerce Product Feed Manager Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the create_item() function in all versions up to, and including, 6.5.6. This makes it possible for authenticated attac...

CVSS:
7.2
Affected:
up to 6.5.6
Fixed in:
6.5.7
Disclosed:
Jul 19, 2024

CVE-2024-38775 on NVD →

WooCommerce Product Feed for Google, Facebook, eBay and Many More <= 3.1.14 - Reflected Cross-Site Scripting

medium

WebAppick WooCommerce Product Feed 3.1.14 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.

CVSS:
6.1
Affected:
up to 3.1.14
Fixed in:
3.1.15
Disclosed:
Aug 30, 2019

CVE-2019-1010124 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database