SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-87919

MEDIUM · CVSS 4.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Product XML Feed Manager for WooCommerce plugin for WordPress prior to version 3.1.1 is vulnerable due to insufficient restrictions on object method calls and user capability checks, enabling users with contributor-level access to delete any WooCommerce product by simply previewing a post containing the shortcode. This flaw poses a significant risk to site integrity and product management. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-87919
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%
WordPress

Original NVD Description

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.