Cross-Site Request Forgery in WooCommerce Product Feed PRO by AdTribes
CVE-2026-3499
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-3499?
The Product Feed PRO for WooCommerce plugin by AdTribes contains a vulnerability that allows unauthenticated attackers to exploit missing or incorrect nonce validation. This issue affects versions 13.4.6 through 13.5.2.1 and involves several AJAX functions, including those responsible for migrating feed settings, clearing caches, rewriting file URLs, and managing legacy filters. Attackers can potentially execute malicious actions if they can trick a site administrator into clicking a crafted link.
Affected Version(s)
Product Feed PRO for WooCommerce by AdTribes β Product Feeds for WooCommerce 13.4.6 <= 13.5.2.1