Time-based SQL Injection Vulnerability in Google Feed Manager for WooCommerce by WordPress
CVE-2026-19778
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-19778?
The Google Feed Manager for WooCommerce plugin is susceptible to time-based SQL Injection due to inadequate escaping of the 'feed' parameter in all versions up to 2.23.7. This vulnerability allows authenticated attackers with administrator privileges to inject additional SQL commands into existing queries. As a result, sensitive information from the database could be compromised. Proper validation and sanitization of user inputs are essential to mitigate this risk.
Affected Version(s)
WPMR Google Feed Manager for WooCommerce β Sell on Google Merchant Center & Shopping 0 <= 2.23.7