cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forbest-woocommerce-feed best-woocommerce-feed

Direction: ascending
Jun 07, 2024

Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces # CVE-2023-52144

CVE, Research URL

CVE-2023-52144

Date
Apr 15, 2024
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.
Affected versions
max 7.3.16.
Status
vulnerable

Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces # 6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76

Date
-
Research Description
Product Feed Manager For WooCommerce &#8211; Sell on 200+ Online Marketplaces [best-woocommerce-feed] < 2.2.3.1 Freemius Library &lt; 2.2.4 - Subscriber+ Arbitrary Option Update The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
Affected versions
max 2.2.3.1.
Status
vulnerable
Jun 13, 2026

Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces # CVE-2023-33999

CVE, Research URL

CVE-2023-33999

Date
Jun 11, 2026
Research Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
Affected versions
max 3.0.
Status
vulnerable
Jun 16, 2026

Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces # 7e57cd4f4859826de00a8e2b09ee24fb7f2d824b

Date
Feb 25, 2019
Research Description
Product Feed Manager For WooCommerce &#8211; Sell on 200+ Online Marketplaces [best-woocommerce-feed] < 2.2.3.1 Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.
Affected versions
max 2.2.3.1.
Status
vulnerable
Jul 17, 2026

Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces # CVE-2026-15306

CVE, Research URL

CVE-2026-15306

Date
Jul 16, 2026
Research Description
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 7.6.2.
Status
vulnerable