Junglewise Threat Intelligence

CVE-2026-9331: WordPress EDD Product Catalog Feed privilege escalation

CVE-2026-9331 · Severity: high · CVSS 7.1 · Published 2026-09-08

Vendors: PixelYourSite.

Executive brief

The EDD Product Catalog Feed plugin for WordPress is used by online retailers to publish Easy Digital Downloads products to Google Merchant Center. The plugin fails to verify user permissions on a feed deletion function, allowing subscribers and other low-privilege users to delete critical site settings. An attacker can exploit this to remove configuration options, causing the website to display errors or become unavailable to customers.

Technical details

The vulnerability is a missing capability check in the wpeddpcf_delete_feed function, allowing authenticated but unprivileged users (subscriber-level and above) to delete arbitrary WordPress option values via an unprotected AJAX or POST handler. The root cause is insufficient authorization validation before performing the deletion action. An attacker with a subscriber account can call this function directly to remove options, such as those controlling feed configuration or critical site settings, triggering denial of service. Attack vector is network-based and requires only an authenticated session; no special privileges or admin credentials are needed. The vulnerability affects all versions up to and including 1.0.2.

Affected products

  • PixelYourSite EDD Product Catalog Feed up to and including 1.0.2

Timeline

  • 2026-09-08: disclosed

References