{"api_version":"1","generated_at":"2026-09-12T10:29:28+00:00","cve":"CVE-2026-87919","urls":{"html":"https://cve.report/CVE-2026-87919","api":"https://cve.report/api/cve/CVE-2026-87919.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-87919","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87919"},"summary":{"title":"Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode","description":"The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-12 06:16:28","updated_at":"2026-09-12 06:16:28"},"problem_types":["CWE-862 Missing Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/2e2f48d3-9106-4357-beec-4dbea02223dc/","name":"https://wpscan.com/vulnerability/2e2f48d3-9106-4357-beec-4dbea02223dc/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87919","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87919","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Product XML Feed Manager for WooCommerce","version":"affected 3.1.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Abdullah Kareem (cyberkareem)","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Product XML Feed Manager for WooCommerce","vendor":"Unknown","versions":[{"lessThan":"3.1.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Abdullah Kareem (cyberkareem)"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode."}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-12T06:00:13.758Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/2e2f48d3-9106-4357-beec-4dbea02223dc/"}],"source":{"discovery":"EXTERNAL"},"title":"Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-87919","datePublished":"2026-09-12T06:00:13.758Z","dateReserved":"2026-09-09T16:01:19.136Z","dateUpdated":"2026-09-12T06:00:13.758Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-12 06:16:28","lastModifiedDate":"2026-09-12 06:16:28","problem_types":["CWE-862 Missing Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"87919","Ordinal":"1","Title":"Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ ","CVE":"CVE-2026-87919","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"87919","Ordinal":"1","NoteData":"The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.","Type":"Description","Title":"Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ "}]}}}