<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>EDD Product Catalog Feed (&lt;= 1.0.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/edd-product-catalog-feed--1.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 11:40:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/edd-product-catalog-feed--1.0.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Vulnerability in EDD Product Catalog Feed Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-9331/</link><pubDate>Tue, 08 Sep 2026 11:40:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-9331/</guid><description>An improper authorization vulnerability in the EDD Product Catalog Feed plugin allows authenticated subscribers to delete arbitrary site options, leading to a denial of service.</description><content:encoded><![CDATA[<p>The EDD Product Catalog Feed plugin for WordPress, developed by PixelYourSite, contains a critical authorization flaw identified as CVE-2026-9331. The vulnerability exists within the wpeddpcf_delete_feed function, which lacks appropriate capability checks. All versions up to and including 1.0.2 are affected. This flaw permits any authenticated user, including those with minimal subscriber-level permissions, to invoke the function and delete arbitrary option values from the WordPress database. By targeting critical site configuration options, an attacker can trigger internal server errors or catastrophic site misconfigurations, effectively resulting in a denial-of-service condition for legitimate users and administrators. This vulnerability highlights the necessity of strict privilege verification for all administrative actions within WordPress plugins.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers to perform unauthorized modification of site settings. By deleting essential options, attackers can render the WordPress site inaccessible or non-functional, causing significant service disruption. The risk is heightened by the low level of access required to exploit the flaw, as any user account can trigger the deletion.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the EDD Product Catalog Feed plugin to the latest version available that addresses this authorization flaw. Ensure that site administrators audit plugin-related database activity to identify unauthorized modifications to the wp_options table. Restrict registration for untrusted users to minimize the pool of potential attackers who could exploit this flaw.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>wordpress</category><category>plugin-vulnerability</category><category>denial-of-service</category></item></channel></rss>