Impact
The Product XML Feed Manager for WooCommerce plugin prior to version 3.1.1 fails to restrict the method invoked by its product shortcode and does not verify a user’s capability against the target product. As a result, any contributor can delete any WooCommerce product by previewing a post containing the shortcode, leading to loss of inventory listings, potential revenue impact, and damage to data integrity.
Affected Systems
The vulnerability affects installations of the WordPress plugin Product XML Feed Manager for WooCommerce. Users with contributor-level access and the ability to edit or preview posts that include the product shortcode are required for exploitation.
Risk and Exploitability
The CVSS score of 4.9 and EPSS score of < 1% indicate a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only legitimate contributor permissions and post preview access, without external network interaction, so the attack surface is limited to the local WordPress environment.
OpenCVE Enrichment