Junglewise Threat Intelligence

CVE-2026-19778: WPMR Google Feed Manager for WooCommerce SQL injection via feed parameter

CVE-2026-19778 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Executive brief

The WPMR Google Feed Manager for WooCommerce plugin, used to sync product data with Google's merchant platform, contains a SQL injection vulnerability that allows authenticated administrators to extract sensitive database information. An attacker with admin credentials could abuse the vulnerability to read or manipulate database records, potentially exposing customer data or product information stored in the WordPress database.

Technical details

This is a time-based SQL injection vulnerability in the 'feed' parameter, affecting all versions up to and including 2.23.7. The root cause is insufficient escaping and preparation of user-supplied input in SQL queries (visible in the class-wppfm-ajax-data.php and class-wppfm-data.php files). The vulnerability requires authentication with administrator-level access; an attacker with admin credentials can append additional SQL queries to extract sensitive data. Detection is possible via time-based SQLi techniques where query execution delays confirm successful injection. A patch addressing the input escaping is expected in versions after 2.23.7.

Affected products

  • WPMR Google Feed Manager for WooCommerce up to and including 2.23.7

Timeline

  • 2026-09-09: disclosed

References