CVE-2026-15095 | wahid0003 Product Feed Manager Plugin up to 6.6.43 on WordPress API call save_feed_config unlink provider path traversal

SecurityVulns

A vulnerability, which was classified as problematic, was found in wahid0003 Product Feed Manager Plugin up to 6.6.43 on WordPress. The impacted element is the function unlink of the file /wp-json/ctxfeed/v1/make_feed/save_feed_config of the component API call Handler. Executing a manipulation of the argument provider can lead to path traversal.

This vulnerability is tracked as CVE-2026-15095. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More