Back

HIGH

Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure

Published Aug 15, 2026

Description

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Jul 22, 2026

CISA Vulnrichment

Updated Aug 17, 2026

NVD

Status Deferred
Modified Aug 26, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Aug 15, 2026
Updated Aug 17, 2026

GitHub

No data