CVE-2026-66580: WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability
Published Sep 17, 2026
·Updated
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Affected Software
1 affected component
WordPress Product Feed Manager<=7.12.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Product Feed Manager pluginto a version that resolves this vulnerability.Fixed in 7.12.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level privileges. No user interaction is required, and the attack can be performed remotely.
2
What is the potential impact if the vulnerability is exploited?
Successful exploitation can expose highly sensitive data and may cause a limited availability impact. The vulnerability has a CVSS severity of High (8.5) and affects the scope beyond the vulnerable component.
3
Which plugin versions are affected?
Product Feed Manager versions 7.12.0 and earlier are affected.