Unauthorized Plugin Installation Vulnerability in WooCommerce Product Feed Manager by WebAppick
CVE-2025-12975
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-12975?
The WooCommerce Product Feed Manager plugin developed by WebAppick is prone to a significant security vulnerability that allows authenticated users with Shop Manager-level access or higher to install arbitrary plugins without proper authorization. This issue arises from a missing capability check in the woo_feed_plugin_installing() function, exposing the system to potential remote code execution threats. Users are advised to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Product Feed Manager for WooCommerce β CTX Feed β Support 220+ Shopping & Social Channels 0 <= 6.6.11