Impact
The Product Feed PRO for WooCommerce plugin insufficiently verifies that callers are authorized before serving data on certain REST read endpoints. This omission allows any internet user to retrieve a store’s feed configuration—including rules, filters, and field mapping—as well as the complete product category taxonomy. The exposed data provides insight into how the shop organizes and presents products, and could be leveraged by a malicious actor to assist in further attacks or glean business information. The vulnerability directly impacts confidentiality but does not allow code execution or overt disruption of services.
Affected Systems
AdTribes’ Product Feed PRO for WooCommerce plugin versions earlier than 13.5.7 are affected. The vulnerability is limited to the REST API provided by the plugin; no other components are mentioned.
Risk and Exploitability
The EPSS score for this issue is not available, and the vulnerability is not listed in the CISA KEV catalog. The absence of an authentication check on a publicly reachable REST endpoint suggests that exploitation is straightforward and can be performed over the network by any unauthenticated user. While the CVSS score is not provided, the risk is that attackers can obtain detailed configuration and taxonomy data, which could facilitate targeted attacks or competitive intelligence gathering. The exploitability is high because the attacker needs only to know the API endpoint URL.
OpenCVE Enrichment