Impact
A contributor path SQL injection flaw exists in the WordPress Product Feed Manager plugin in versions up to 7.12.0. Unsanitized input can be used to inject arbitrary SQL statements, allowing attackers to read, modify, or delete sensitive data stored in the WordPress database. The weakness is identified as CWE‑89 and carries a CVSS score of 8.5, reflecting a high impact if successfully exploited.
Affected Systems
The vulnerability affects the RexTheme Product Feed Manager plugin for WordPress. Any deployment using version 7.12.0 or earlier is susceptible. No additional version details are provided beyond the cutoff version 7.12.0.
Risk and Exploitability
The EPSS score is not available, but the high CVSS indicates significant risk. Attackers would need to send crafted requests to the plugin’s endpoints, which are externally reachable over the web. The likely attack vector is remote, via HTTP query parameters or form inputs that the plugin processes without proper validation.
OpenCVE Enrichment