CVE 7.2 HIGH

CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation_CVE-2025-12975

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to install arbitrary plugins which can be leveraged to achieve remote code execution.

Basic Information

ID CVE-2025-12975
Source Wordfence
Published Feb 19, 2026 at 04:36

Affected Product

Vendor wahid0003
Product Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels
Version *
Affected Versions wahid0003 Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.