| CVE-2026-3499 | Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions | jkohlbach | Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce | High | 8.8 | 2026-04-08 01:24:44 | Deep Dive |
| CVE-2026-22480 | WordPress Product Feed for WooCommerce plugin <= 2.3.3 - PHP Object Injection vulnerability | WebToffee | Product Feed for WooCommerce | High | 7.2 | 2026-03-25 16:14:22 | Deep Dive |
| CVE-2026-32443 | WordPress Product Feed PRO for WooCommerce plugin <= 13.5.2 - Cross Site Request Forgery (CSRF) vulnerability | Josh Kohlbach | Product Feed PRO for WooCommerce | 中危 | - | 2026-03-13 11:42:20 | Deep Dive |
| CVE-2025-12975 | CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation | wahid0003 | Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels | High | 7.2 | 2026-02-19 04:36:11 | Deep Dive |
| CVE-2025-66089 | WordPress Product Feed for WooCommerce plugin <= 2.3.1 - Broken Access Control vulnerability | WebToffee | Product Feed for WooCommerce | Medium | 4.3 | 2025-11-21 12:29:59 | Deep Dive |
| CVE-2025-10046 | ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction | elextensions | ELEX WooCommerce Google Shopping (Google Product Feed) | Medium | 4.9 | 2025-09-06 06:43:00 | Deep Dive |
| CVE-2025-49887 | WordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) Vulnerability | WPFactory | Product XML Feed Manager for WooCommerce | Critical | 9.9 | 2025-08-14 10:34:07 | Deep Dive |
| CVE-2025-30959 | WordPress Product XML Feed Manager for WooCommerce <= 2.9.2 - Broken Access Control Vulnerability | WPFactory | Product XML Feed Manager for WooCommerce | Medium | 6.5 | 2025-07-16 11:28:08 | Deep Dive |
| CVE-2025-49287 | WordPress Product Feed for WooCommerce plugin <= 2.2.8 - Broken Access Control Vulnerability | WebToffee | Product Feed for WooCommerce | Medium | 4.3 | 2025-06-06 12:53:43 | Deep Dive |
| CVE-2025-47643 | WordPress ELEX Product Feed for WooCommerce plugin <= 3.1.2 - SQL Injection Vulnerability | ELEXtensions | ELEX Product Feed for WooCommerce | High | 7.6 | 2025-05-07 14:20:42 | Deep Dive |
| CVE-2024-32513 | WordPress Product Feed PRO for WooCommerce plugin <= 13.3.1 - Sensitive Data Exposure vulnerability | AdTribes.io | Product Feed PRO for WooCommerce | Medium | 5.3 | 2024-04-17 08:03:24 | Deep Dive |
| CVE-2024-32087 | WordPress Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More plugin <= 3.5.7 - Auth. SQL Injection (SQLi) vulnerability | ExportFeed.com | Product Feed on WooCommerce for Google | High | 7.6 | 2024-04-15 07:40:55 | Deep Dive |
| CVE-2024-24800 | WordPress Product Feed PRO for WooCommerce plugin <= 13.2.5 - Reflected Cross Site Scripting (XSS) vulnerability | AdTribes.io | Product Feed PRO for WooCommerce | High | 7.1 | 2024-03-27 05:47:15 | Deep Dive |
| CVE-2022-46793 | WordPress Product Feed PRO for WooCommerce Plugin <= 12.4.4 is vulnerable to Cross Site Request Forgery (CSRF) | AdTribes.io | Product Feed PRO for WooCommerce | Medium | 5.4 | 2023-04-06 12:44:09 | Deep Dive |
| CVE-2022-46797 | WordPress Conversios.io Plugin <= 5.2.3 is vulnerable to Cross Site Request Forgery (CSRF) | Conversios | All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce | Medium | 5.4 | 2023-03-01 13:43:23 | Deep Dive |
| CVE-2021-25068 | Sync WooCommerce Product feed to Google Shopping <= 1.2.4 - Admin+ SQLi | Unknown | Sync WooCommerce Product feed to Google Shopping | 高危 | - | 2022-03-28 17:21:55 | Deep Dive |
| CVE-2022-0426 | Product Feed PRO for WooCommerce < 11.2.3 - Reflected Cross-Site Scripting | Unknown | Product Feed PRO for WooCommerce | 中危 | - | 2022-03-07 08:16:36 | Deep Dive |
| CVE-2021-24974 | Product Feed PRO for WooCommerce < 11.0.7 - Subscriber+ Settings Update to Stored XSS | Unknown | Product Feed PRO for WooCommerce | 中危 | - | 2022-01-24 08:01:00 | Deep Dive |
| CVE-2021-24511 | Create WooCommerce Product Feeds For 40+ Merchants < 3.3.1.0 - Authenticated SQL Injection | Unknown | Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More | 高危 | - | 2021-09-20 10:06:13 | Deep Dive |
| CVE-2019-1010124 | WebAppick WooCommerce Product Feed 跨站脚本漏洞 | WebAppick | WooCommerce Product Feed | 中危 | - | 2019-07-23 00:00:00 | Deep Dive |