Cross-Site Request Forgery in WooCommerce Product Feed PRO by AdTribes
CVE-2026-3499

8.8HIGH

What is CVE-2026-3499?

The Product Feed PRO for WooCommerce plugin by AdTribes contains a vulnerability that allows unauthenticated attackers to exploit missing or incorrect nonce validation. This issue affects versions 13.4.6 through 13.5.2.1 and involves several AJAX functions, including those responsible for migrating feed settings, clearing caches, rewriting file URLs, and managing legacy filters. Attackers can potentially execute malicious actions if they can trick a site administrator into clicking a crafted link.

Affected Version(s)

Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce 13.4.6 <= 13.5.2.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lucky_buddy
.