Executive brief
Product Feed Manager is a WordPress plugin that manages product feeds for e-commerce sites. A SQL injection vulnerability in the contributor-level functionality allows authorized users to read, modify, or delete the entire site database, including customer accounts and private business data. The vulnerability affects versions up to 7.12.0 and has been patched in 7.12.1.
Technical details
The vulnerability is a SQL injection flaw in the Product Feed Manager WordPress plugin affecting versions 7.12.0 and earlier. It exists in functionality accessible to users with contributor-level privileges, allowing them to inject arbitrary SQL commands. An authenticated attacker with contributor rights can exploit this to read, modify, or delete any data in the WordPress database. The vulnerability does not require network access beyond normal WordPress authentication; however, it does require valid contributor-level credentials. A patch is available in version 7.12.1.
Affected products
- WPFunnels Team Product Feed Manager <= 7.12.0
Timeline
- 2026-09-10: disclosed: Reported to Patchstack by John Ryan Albon
- 2026-09-17: advisory: Published by Patchstack
- 2026-09-17: patched: Fixed in version 7.12.1