PT-2026-72164 · Adtribes · Product Feed Pro For Woocommerce
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Product Feed PRO for WooCommerce by AdTribes versions prior to 13.5.7
Description
An authorization check is missing on a REST read route, which allows unauthenticated users to disclose the store's feed configuration, including rules, filters, and field mapping. Additionally, this issue enables the enumeration of the full product category taxonomy.
Recommendations
Update Product Feed PRO for WooCommerce by AdTribes to version 13.5.7 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Product Feed Pro For Woocommerce