Unauthenticated Arbitrary File Write Vulnerability in PrestaShop's Google Merchant Center Feed Module
CVE-2026-85520

9.3CRITICAL

Key Information:

Vendor

Mypresta

Vendor
CVE Published:
29 September 2026

What is CVE-2026-85520?

The Google Merchant Center Feed module for PrestaShop has a security flaw that permits unauthenticated attackers to exploit the feed.php endpoint. By manipulating request parameters, an attacker can dictate the output file name, path, extension, and content, which leads to a lack of proper input validation and authentication. This vulnerability allows the execution of arbitrary PHP code, culminating in potential remote code execution (RCE). It is essential for users to upgrade to version 2.3.9 or higher to mitigate this security risk.

Affected Version(s)

Google Merchant Center Feed 1.9.1 <= 2.3.8

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Today Group sp. z o.o.
.