Impact
The vulnerability allows an authenticated attacker with shop‑manager level or higher access to perform a directory traversal using the 'provider' parameter. The exploit requires a two‑step REST API sequence that first stores a malicious path in the wp_options table and then calls a deletion endpoint, which unlinks files whose extensions match a whitelist. Deleting essential files can give the attacker the ability to execute arbitrary code on the server.
Affected Systems
WordPress sites that have the Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels plugin installed with a version up to and including 6.6.43. Any instance of this plugin is vulnerable until it is updated beyond that version.
Risk and Exploitability
With a CVSS score of 4.9 the vulnerability is considered moderate in severity. The EPSS score is 1%, and the issue is not listed in the CISA KEV catalog, so the likelihood of public exploitation is unclear. However, the attack requires authenticated access, which limits the threat to insiders or compromised accounts, but the potential for file deletion that can lead to remote code execution makes it a significant concern for sites that rely on this plugin.
OpenCVE Enrichment