Impact
This vulnerability is an improper control of code generation flaw (CWE‑94) that allows remote code inclusion. An attacker can insert malicious code into the XML feed management process, resulting in arbitrary code execution on the web server. The impact is full compromise of the site, including data theft, defacement, or further propagation.
Affected Systems
The affected product is WPFactory’s Product XML Feed Manager for WooCommerce plugin, any release from the earliest available through version 2.9.3. All WordPress sites that have installed the plugin at these versions are vulnerable.
Risk and Exploitability
The CVSS score of 9.9 marks this as critical, while the EPSS score of less than 1% indicates low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s XML feed handling interface, where a malicious XML payload could trigger code inclusion. Exploitation requires no special privileges and can be performed remotely by sending crafted data to the plugin.
OpenCVE Enrichment
EUVD