# CVE-2026-87919

## Summary

- **CVE ID:** CVE-2026-87919
- **Severity:** MEDIUM
- **CVSS Score:** 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N)
- **CWE:** N/A
- **Published:** Sep 12, 2026
- **Last Modified:** Sep 12, 2026

## Description

The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.

## Affected Products

- Unknown — Product XML Feed Manager for WooCommerce (0)

## References

- [CNA](https://wpscan.com/vulnerability/2e2f48d3-9106-4357-beec-4dbea02223dc/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._