Impact
The vulnerability is caused by a missing capability check in the woo_feed_plugin_installing() function, which allows any authenticated user with Shop Manager or higher privileges to install arbitrary WordPress plugins. This can be leveraged to deploy malicious code, enabling remote code execution against the site. The weakness is a classic authorization bypass, identified as CWE‑862.
Affected Systems
The affected product is the CTX Feed – WooCommerce Product Feed Manager plugin for WordPress, with all releases up to and including 6.6.11. The vendor is wahid0003:Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping Social Channels. Sites running these versions are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, meaning no known in‑use exploits have been widely reported. The likely attack vector requires authenticated access with Shop Manager capabilities, so the threat surface depends on how many users are granted that role.
OpenCVE Enrichment