Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels <= 6.6.46 - Authenticated (Shop Manager+) Arbitrary File Downloaf
medium
The Product Feed Manager for WooCommerce – CTXFeed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.6.46. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to read the contents of arbitrary...
- CVSS:
- 4.9
- Affected:
- up to 6.6.46
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2026
CVE-2026-73383 on NVD →
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels <= 6.6.42 - Authenticated (Shop Manager+) Remote Code Execution
high
The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.6.42. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to execute code on the ser...
- CVSS:
- 7.2
- Affected:
- up to 6.6.42
- Fixed in:
- 6.6.43
- Disclosed:
- Aug 4, 2026
CVE-2026-66709 on NVD →
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels <= 6.6.26 - Authenticated (Shop Manager+) PHP Object Injection
medium
The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.6.26 via deserialization of untrusted input. This makes it possible for authenticated attackers, with shop manager-level access and...
- CVSS:
- 6.6
- Affected:
- up to 6.6.26
- Fixed in:
- 6.6.27
- Disclosed:
- Apr 7, 2026
CVE-2026-39434 on NVD →
CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation
high
The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop Mana...
- CVSS:
- 7.2
- Affected:
- up to 6.6.11
- Fixed in:
- 6.6.12
- Disclosed:
- Feb 18, 2026
CVE-2025-12975 on NVD →
CTX Feed <= 6.6.18 - Missing Authorization
medium
The CTX Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.6.18. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.6.18
- Fixed in:
- 6.6.19
- Disclosed:
- Jan 4, 2026
CVE-2026-22461 on NVD →
CTX Feed <= 6.5.6 - Authenticated (Shop Manager+) Arbitrary Options Update
high
The CTX Feed – WooCommerce Product Feed Manager Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the create_item() function in all versions up to, and including, 6.5.6. This makes it possible for authenticated attac...
- CVSS:
- 7.2
- Affected:
- up to 6.5.6
- Fixed in:
- 6.5.7
- Disclosed:
- Jul 19, 2024
CVE-2024-38775 on NVD →
WooCommerce Product Feed for Google, Facebook, eBay and Many More <= 3.1.14 - Reflected Cross-Site Scripting
medium
WebAppick WooCommerce Product Feed 3.1.14 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.
- CVSS:
- 6.1
- Affected:
- up to 3.1.14
- Fixed in:
- 3.1.15
- Disclosed:
- Aug 30, 2019
CVE-2019-1010124 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database