What is CVE-2026-15258?
CVE-2026-15258 is an SQL injection vulnerability in the Product Feed Manager for WooCommerce plugin before version 7.6.1, caused by improper sanitization of custom filter rules. It allows users with Contributor role and above to manipulate SQL queries, potentially compromising the database. Updating the plugin to version 7.6.1 or later is recommended.
Azərbaycanca: CVE-2026-15258, WooCommerce üçün Product Feed Manager plaginin 7.6.1-dən əvvəlki versiyalarında aşkar edilmiş SQL injection zəifliyidir. Bu zəiflik Contributor və daha yuxarı rollu istifadəçilərə xüsusi filter qaydaları vasitəsilə SQL sorğularına müdaxilə etməyə imkan verir. Plagini 7.6.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Product Feed Manager plugin are affected by CVE-2026-15258?
This SQL injection vulnerability affects plugin versions prior to 7.6.1.
What is the minimum user role required to exploit CVE-2026-15258?
A Contributor role or higher is required to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.