CVE-2025-49887: WordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) Vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclusion. This issue affects Product XML Feed Manager for WooCommerce: from n/a through 2.9.3.
Other sources
Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Remote Code Inclusion.This issue affects Product XML Feed Manager for WooCommerce: from n/a through <= 2.9.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49887?
CVE-2025-49887 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-49887?
To fix CVE-2025-49887, upgrade the Product XML Feed Manager for WooCommerce to version 2.9.4 or later.
What type of vulnerability is CVE-2025-49887?
CVE-2025-49887 is an improper control of generation of code vulnerability, specifically a code injection issue.
Which software is affected by CVE-2025-49887?
CVE-2025-49887 affects the Product XML Feed Manager for WooCommerce version 2.9.3 and earlier.
Can CVE-2025-49887 lead to unauthorized access?
Yes, CVE-2025-49887 can lead to unauthorized access through remote code inclusion.