Unauthorized Plugin Installation Vulnerability in WooCommerce Product Feed Manager by WebAppick
CVE-2025-12975
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-12975?
The WooCommerce Product Feed Manager plugin developed by WebAppick is prone to a significant security vulnerability that allows authenticated users with Shop Manager-level access or higher to install arbitrary plugins without proper authorization. This issue arises from a missing capability check in the woo_feed_plugin_installing() function, exposing the system to potential remote code execution threats. Users are advised to upgrade to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Product Feed Manager for WooCommerce β CTX Feed β Support 220+ Shopping & Social Channels * <= 6.6.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved