CVE-2026-15258

CVE-2026-15258: Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter

Vendor Unknown
Product Product Feed Manager For WooCommerce
Published July 31, 2026
Last update July 31, 2026

CVSS base score

What the vulnerability does

01Description

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

Key dates

02Disclosure timeline

July 31, 2026 CVE published
July 31, 2026 Record updated