THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-87919 (MEDIUM 4.9) — The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerc

[NVD] CVE-2026-87919 (MEDIUM 4.9) — The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerc

mednvdPublished 2026-09-12

CVE-2026-87919 CVSS: 4.9 MEDIUM Published: 2026-09-12T06:16:28.537

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the sh

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87919