---
id: CVE-2026-87919
title: >-
  The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1
  does not restrict which object method its product shortcode may call, nor
  check the user's capability over the targeted product, allowing users with
  contributor-…
summary: >-
  The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1
  does not restrict which object method its product shortcode may call, nor
  check the user's capability over the targeted product, allowing users with
  contributor-…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
product: Product XML Feed Manager for WooCommerce
affected:
  - product_xml_feed_manager_for_woocommerce < 3.1.1
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87919'
references:
  - url: 'https://wpscan.com/vulnerability/2e2f48d3-9106-4357-beec-4dbea02223dc/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00331
epssPercentile: 0.23572
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-12T15:14:18.937145Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
