Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-24778 | Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclusion. This issue affects Product XML Feed Manager for WooCommerce: from n/a through 2.9.3. |
Solution
Update the WordPress Product XML Feed Manager for WooCommerce plugin to the latest available version (at least 2.9.4).
Workaround
No workaround given by the vendor.
Sat, 16 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress Wpfactory Wpfactory product Xml Feed Manager For Woocommerce |
|
Vendors & Products |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress Wpfactory Wpfactory product Xml Feed Manager For Woocommerce |
Thu, 14 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 14 Aug 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclusion. This issue affects Product XML Feed Manager for WooCommerce: from n/a through 2.9.3. | |
Title | WordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) Vulnerability | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-08-14T15:57:08.929Z
Reserved: 2025-06-11T16:06:23.852Z
Link: CVE-2025-49887

Updated: 2025-08-14T15:57:05.058Z

Status : Awaiting Analysis
Published: 2025-08-14T11:15:40.827
Modified: 2025-08-14T13:11:53.633
Link: CVE-2025-49887

No data.

Updated: 2025-08-16T21:41:21Z