Directory Traversal Vulnerability in Product Feed Manager for WooCommerce by WebAppick
CVE-2026-15095
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-15095?
The Product Feed Manager for WooCommerce β CTX Feed plugin for WordPress suffers from a directory traversal vulnerability due to improper validation of the 'provider' parameter. This flaw allows authenticated users with shop manager-level access to craft malicious requests that can lead to the deletion of arbitrary files on the server. The exploitation process involves making two REST API calls to manipulate the application's settings and ultimately trigger file deletions. The affected plugin only permits deletions of specific file types, which could potentially result in remote code execution if critical files are removed from the system.
Affected Version(s)
Product Feed Manager for WooCommerce β CTX Feed β Support 220+ Shopping, AI & Social Channels 0 <= 6.6.43