Time-based SQL Injection Vulnerability in Google Feed Manager for WooCommerce by WordPress
CVE-2026-19778

6.5MEDIUM

What is CVE-2026-19778?

The Google Feed Manager for WooCommerce plugin is susceptible to time-based SQL Injection due to inadequate escaping of the 'feed' parameter in all versions up to 2.23.7. This vulnerability allows authenticated attackers with administrator privileges to inject additional SQL commands into existing queries. As a result, sensitive information from the database could be compromised. Proper validation and sanitization of user inputs are essential to mitigate this risk.

Affected Version(s)

WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping 0 <= 2.23.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.