Directory Traversal Vulnerability in Product Feed Manager for WooCommerce by WebAppick
CVE-2026-15095

4.9MEDIUM

What is CVE-2026-15095?

The Product Feed Manager for WooCommerce – CTX Feed plugin for WordPress suffers from a directory traversal vulnerability due to improper validation of the 'provider' parameter. This flaw allows authenticated users with shop manager-level access to craft malicious requests that can lead to the deletion of arbitrary files on the server. The exploitation process involves making two REST API calls to manipulate the application's settings and ultimately trigger file deletions. The affected plugin only permits deletions of specific file types, which could potentially result in remote code execution if critical files are removed from the system.

Affected Version(s)

Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels 0 <= 6.6.43

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.