CVE 9.9 CRITICAL

WordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) Vulnerability_CVE-2025-49887

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclusion. This issue affects Product XML Feed Manager for WooCommerce: from n/a through 2.9.3.

Basic Information

ID CVE-2025-49887
Source Patchstack
Published Aug 14, 2025 at 10:34

Affected Product

Vendor WPFactory
Product Product XML Feed Manager for WooCommerce
Version n/a
Affected Versions WPFactory Product XML Feed Manager for WooCommerce n/a

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.