cleantalk
Vulnerabilities and Security Researches

Product Feed for WooCommerce – Google Shops, Facebook Shop, TikTok, Instagram, and More, CVE-2025-66089

CVE, Research URL

CVE-2025-66089

Published on
Nov 21, 2025
Research Description
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1.
Affected versions
max 2.3.1.
Status
vulnerable