Executive brief
The Product Feed Manager For WooCommerce plugin for WordPress, which helps merchants sync products with online marketplaces, is vulnerable to a security flaw. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of sensitive session information or unauthorized actions performed on behalf of the user.
Technical details
The Product Feed Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 's' search parameter. An unauthenticated attacker can exploit this by crafting a malicious URL containing a script payload and tricking a user (such as an administrator) into clicking it. When the victim visits the link, the arbitrary script executes within the context of their browser session. This can be used to hijack sessions, redirect users, or modify site content. The vulnerability affects all versions up to and including 7.6.1.
Affected products
- rextheme Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces <= 7.6.1
Timeline
- 2026-07-16: disclosed: Initial NVD publication date
References
- https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/admin/class-rex-product-feed-actions.php
- https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/admin/class-rex-product-feed-actions.php
- https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/admin/class-rex-product-feed-actions.php
- https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/includes/class-rex-product-feed.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3607243%40best-woocommerce-feed&new=3607243%40best-woocommerce-feed
- https://www.wordfence.com/threat-intel/vulnerabilities/id/10207866-6615-486b-a60a-a522ed8a0285?source=cve