Description
The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Product Feed PRO for WooCommerce plugin insufficiently verifies that callers are authorized before serving data on certain REST read endpoints. This omission allows any internet user to retrieve a store’s feed configuration—including rules, filters, and field mapping—as well as the complete product category taxonomy. The exposed data provides insight into how the shop organizes and presents products, and could be leveraged by a malicious actor to assist in further attacks or glean business information. The vulnerability directly impacts confidentiality but does not allow code execution or overt disruption of services.

Affected Systems

AdTribes’ Product Feed PRO for WooCommerce plugin versions earlier than 13.5.7 are affected. The vulnerability is limited to the REST API provided by the plugin; no other components are mentioned.

Risk and Exploitability

The EPSS score for this issue is not available, and the vulnerability is not listed in the CISA KEV catalog. The absence of an authentication check on a publicly reachable REST endpoint suggests that exploitation is straightforward and can be performed over the network by any unauthenticated user. While the CVSS score is not provided, the risk is that attackers can obtain detailed configuration and taxonomy data, which could facilitate targeted attacks or competitive intelligence gathering. The exploitability is high because the attacker needs only to know the API endpoint URL.

Generated by OpenCVE AI on August 15, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Product Feed PRO for WooCommerce to version 13.5.7 or newer, which includes the required authorization checks on the affected REST routes.
  • If immediate update is not possible, restrict access to the plugin’s REST API endpoints by applying network‑level access controls or using a firewall rule to allow only authenticated traffic. This mitigates the risk until the patch can be applied.
  • Verify that no other unauthenticated REST routes remain, and consider disabling the plugin’s REST interface if it is not needed for normal operation.

Generated by OpenCVE AI on August 15, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Adtribes
Adtribes product Feed Pro For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Adtribes
Adtribes product Feed Pro For Woocommerce
Wordpress
Wordpress wordpress

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.
Title Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
References

Subscriptions

Adtribes Product Feed Pro For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-15T06:00:14.814Z

Reserved: 2026-07-22T14:35:14.017Z

Link: CVE-2026-16611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:17:08.380

Modified: 2026-08-15T06:17:08.380

Link: CVE-2026-16611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T07:30:05Z

Weaknesses

No weakness.