Description
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Published: 2026-09-17
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to unauthorized database access
Action: Patch
AI Analysis

Impact

A contributor path SQL injection flaw exists in the WordPress Product Feed Manager plugin in versions up to 7.12.0. Unsanitized input can be used to inject arbitrary SQL statements, allowing attackers to read, modify, or delete sensitive data stored in the WordPress database. The weakness is identified as CWE‑89 and carries a CVSS score of 8.5, reflecting a high impact if successfully exploited.

Affected Systems

The vulnerability affects the RexTheme Product Feed Manager plugin for WordPress. Any deployment using version 7.12.0 or earlier is susceptible. No additional version details are provided beyond the cutoff version 7.12.0.

Risk and Exploitability

The EPSS score is not available, but the high CVSS indicates significant risk. Attackers would need to send crafted requests to the plugin’s endpoints, which are externally reachable over the web. The likely attack vector is remote, via HTTP query parameters or form inputs that the plugin processes without proper validation.

Generated by OpenCVE AI on September 17, 2026 at 22:12 UTC.

Remediation

Vendor Solution

Update the WordPress Product Feed Manager Plugin to the latest available version (at least 7.12.1).


OpenCVE Recommended Actions

  • Update the WordPress Product Feed Manager plugin to version 7.12.1 or newer.
  • If an immediate update is not possible, disable or remove the plugin from the site to eliminate the attack surface.
  • Implement web‑application firewall rules to block malicious SQL injection signatures targeting the plugin’s input fields.

Generated by OpenCVE AI on September 17, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Rextheme
Rextheme product Feed Manager
Wordpress
Wordpress wordpress
Vendors & Products Rextheme
Rextheme product Feed Manager
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Title WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Rextheme Product Feed Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T19:21:55.178Z

Reserved: 2026-07-27T13:59:59.781Z

Link: CVE-2026-66580

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:31.450Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:16.920

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-66580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:15:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')