WP eBay Product Feeds Security & Risk Analysis

wordpress.org/plugins/ebay-feeds-for-wordpress

Display feeds of eBay Products from eBay Partner Network on your site.

800 active installs v3.4.10 PHP + WP 3.0+ Updated Nov 30, 2025
affiliate-marketingblockebay-partner-feedsebay-partner-networkgutenberg-ready
95
A · Safe
CVEs total4
Unpatched0
Last CVEDec 15, 2025
Safety Verdict

Is WP eBay Product Feeds Safe to Use in 2026?

Generally Safe

Score 95/100

WP eBay Product Feeds has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Dec 15, 2025Updated 4mo ago
Risk Assessment

The 'ebay-feeds-for-wordpress' plugin version 3.4.10 exhibits a mixed security posture. On the positive side, the code analysis reveals no dangerous functions, no raw SQL queries, and a complete absence of external HTTP requests, which are significant security strengths. The plugin also has a decent number of capability checks and a limited attack surface with no unprotected entry points detected in the static analysis. However, a concerning weakness lies in the output escaping, where only 53% of outputs are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities.

The vulnerability history is a significant concern, with a total of 4 known medium-severity CVEs. While currently unpatched CVEs are reported as 0, the historical prevalence of SSRF and XSS vulnerabilities suggests a pattern of past security flaws. The last vulnerability being in late 2025 (though this date seems in the future and might be a data error) warrants attention, as it indicates ongoing security challenges or a recent discovery. The lack of taint analysis results could be due to limitations in the analysis tool or a very specific code structure, but it doesn't negate the identified output escaping issues and historical CVEs.

In conclusion, while the plugin demonstrates good practices in areas like database interaction and external communication, the significant number of past medium-severity vulnerabilities, particularly in SSRF and XSS, coupled with less than ideal output escaping, presents a notable risk. Users should exercise caution and ensure all historical vulnerabilities have been definitively addressed and patched.

Key Concerns

  • Significant number of past medium severity CVEs
  • Low percentage of properly escaped outputs
  • Potential for historical vulnerability types (SSRF, XSS)
Vulnerabilities
4

WP eBay Product Feeds Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
1 CVE in 2023
2023
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2025-67557medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

eBay Product Feeds <= 3.4.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

Dec 15, 2025 Patched in 3.4.10 (5d)
CVE-2025-58977medium · 6.4Server-Side Request Forgery (SSRF)

WP eBay Product Feeds <= 3.4.8 - Authenticated (Contributor+) Server Side Request Forgery

Sep 9, 2025 Patched in 3.4.9 (7d)
CVE-2023-23722medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP eBay Product Feeds <= 3.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jan 19, 2023 Patched in 3.4 (369d)
CVE-2014-4525medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP eBay Product Feeds < 1.1 - Cross-Site Scripting

Apr 25, 2014 Patched in 1.1 (3560d)
Code Analysis
Analyzed Mar 16, 2026

WP eBay Product Feeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
20 escaped
Nonce Checks
0
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped38 total outputs
Attack Surface

WP eBay Product Feeds Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ebayfeedsforwordpress] ebay-feeds-for-wordpress.php:65
WordPress Hooks 24
actioninitebay-feeds-for-wordpress.php:34
actioninitebay-feeds-for-wordpress.php:35
actionplugins_loadedebay-feeds-for-wordpress.php:36
actionplugins_loadedebay-feeds-for-wordpress.php:37
actionwp_headebay-feeds-for-wordpress.php:38
filterwp_ebay_product_feed_urlebay-feeds-for-wordpress.php:39
actionadmin_menuebay-feeds-for-wordpress.php:44
actionadmin_initebay-feeds-for-wordpress.php:45
actionadmin_initebay-feeds-for-wordpress.php:46
filterwp_ebay_product_feed_botsebay-feeds-for-wordpress.php:53
actionplugins_loadedebay-feeds-for-wordpress.php:55
filterwp_feed_cache_transient_lifetimeebay-feeds-for-wordpress.php:68
filterwp_feed_cache_transient_lifetimeebay-feeds-for-wordpress.php:69
actionenqueue_block_editor_assetsebay-feeds-for-wordpress.php:81
actioninitebay-feeds-for-wordpress.php:82
filtermce_external_pluginsinc\admin.php:14
filtermce_buttonsinc\admin.php:15
actionwp_feed_optionsinc\functions.php:24
actionadmin_noticesinc\notices.php:19
actionadmin_noticesinc\notices.php:24
actionadmin_initinc\notices.php:31
actionadmin_initinc\notices.php:91
actionebay_feeds_for_wordpress_added_optionsinc\upgrade.php:40
actionwidgets_initinc\widget.php:108
Maintenance & Trust

WP eBay Product Feeds Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 30, 2025
PHP min version
Downloads101K

Community Trust

Rating94/100
Number of ratings17
Active installs800
Developer Profile

WP eBay Product Feeds Developer Profile

Rhys Wynne

13 plugins · 7K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
476 days
View full developer profile
Detection Fingerprints

How We Detect WP eBay Product Feeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ebay-feeds-for-wordpress/ebay-feeds-for-wordpress-admin.css/wp-content/plugins/ebay-feeds-for-wordpress/ebffwp_option.js/wp-content/plugins/ebay-feeds-for-wordpress/block-editor-plugin.js
Script Paths
/wp-content/plugins/ebay-feeds-for-wordpress/ebffwp_option.js/wp-content/plugins/ebay-feeds-for-wordpress/block-editor-plugin.js
Version Parameters
ebay-feeds-for-wordpress/ebay-feeds-for-wordpress-admin.css?ver=ebay-feeds-for-wordpress/ebffwp_option.js?ver=ebay-feeds-for-wordpress/block-editor-plugin.js?ver=

HTML / DOM Fingerprints

Data Attributes
feeditemsheader
Shortcode Output
[ebayfeedsforwordpress
FAQ

Frequently Asked Questions about WP eBay Product Feeds