Junglewise Threat Intelligence

CVE-2026-15306: RexTheme Product Feed Manager For WooCommerce Reflected XSS in s parameter

CVE-2026-15306 · Severity: medium · CVSS 6.1 · Published 2026-07-16

Executive brief

The Product Feed Manager For WooCommerce plugin for WordPress, which helps merchants sync products with online marketplaces, is vulnerable to a security flaw. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of sensitive session information or unauthorized actions performed on behalf of the user.

Technical details

The Product Feed Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 's' search parameter. An unauthenticated attacker can exploit this by crafting a malicious URL containing a script payload and tricking a user (such as an administrator) into clicking it. When the victim visits the link, the arbitrary script executes within the context of their browser session. This can be used to hijack sessions, redirect users, or modify site content. The vulnerability affects all versions up to and including 7.6.1.

Affected products

  • rextheme Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces <= 7.6.1

Timeline

  • 2026-07-16: disclosed: Initial NVD publication date

References

Related threats