CyberRota Analysis
AI-GeneratedThe Product XML Feed Manager for WooCommerce plugin for WordPress prior to version 3.1.1 is vulnerable due to insufficient restrictions on object method calls and user capability checks, enabling users with contributor-level access to delete any WooCommerce product by simply previewing a post containing the shortcode. This flaw poses a significant risk to site integrity and product management. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.