Executive brief
The Product XML Feed Manager for WooCommerce plugin for WordPress allows contributors and other low-privileged users to permanently delete any product in a WooCommerce store by embedding a specially crafted shortcode in a draft post and previewing it. This can be exploited to sabotage product catalogs or cause business disruption without requiring administrative approval or ownership of the targeted products.
Technical details
The vulnerability is a broken access control flaw (CWE-862) in the plugin's product shortcode handler. The shortcode accepts two attributes—product_id and function—and executes any callable method on the WC_Product object without validating user permissions or restricting which methods may be invoked. An attacker with contributor-level access (a common self-registerable role) can craft a shortcode such as [alg_product_function product_id="N" function="delete"] in a post preview to trigger WC_Product::delete() on an arbitrary product, bypassing WordPress capability checks like delete_others_products. The attack requires only the ability to create draft posts and preview them; no further user interaction is needed. The plugin was patched in version 3.1.1.
Affected products
- Algoritmika Product XML Feed Manager for WooCommerce before 3.1.1
Timeline
- 2026-09-10: disclosed
- 2026-09-12: patched: Fixed in version 3.1.1