Description
Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forgery.This issue affects Product Feed PRO for WooCommerce: from n/a through <= 13.5.2.
Published: 2026-03-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery permitting unauthorized actions
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw that allows an attacker to trick an authenticated user into sending authenticated requests to the WordPress site. From the vendor description, the flaw is present in Product Feed PRO for WooCommerce plugin versions up to 13.5.2. An attacker could cause the plugin to perform privileged actions such as changing feed settings, generating feed data or other administrative functions, thereby impacting the confidentiality, integrity, or availability of the site’s e‑commerce data. The weakness corresponds to CWE‑352.

Affected Systems

Affected systems are WordPress sites that have Josh Kohlbach Product Feed PRO for WooCommerce installed. The plugin versions impacted are those from the initial release through and including 13.5.2. No other versions are listed as affected.

Risk and Exploitability

The vulnerability has a CVSS v3 score of 6.5, indicating moderate severity. The EPSS score is less than 1 %, suggesting a low probability of widespread exploitation at present. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a web‑based client: a user who is logged into the WordPress admin area visits a malicious web page that automatically submits a forged request to the vulnerable plugin. No additional exploitation conditions are noted in the provided data.

Generated by OpenCVE AI on March 19, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update of Product Feed PRO for WooCommerce to a version newer than 13.5.2.
  • If immediate updating is impossible, temporarily disable the plugin or limit access to the WordPress administration area via IP whitelisting or two‑factor authentication.
  • Deploy a web application firewall or security plugin that blocks CSRF requests to unknown or unauthenticated endpoints.
  • Verify that the site’s core WordPress installation and all other plugins are up to date.

Generated by OpenCVE AI on March 19, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Josh Kohlbach
Josh Kohlbach product Feed Pro For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Josh Kohlbach
Josh Kohlbach product Feed Pro For Woocommerce
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forgery.This issue affects Product Feed PRO for WooCommerce: from n/a through <= 13.5.2.
Title WordPress Product Feed PRO for WooCommerce plugin <= 13.5.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Josh Kohlbach Product Feed Pro For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:16:17.713Z

Reserved: 2026-03-12T11:11:35.694Z

Link: CVE-2026-32443

cve-icon Vulnrichment

Updated: 2026-03-13T15:35:46.312Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:55:04.880

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T12:03:21Z

Weaknesses