Unauthenticated Arbitrary File Write Vulnerability in PrestaShop's Google Merchant Center Feed Module
CVE-2026-85520
9.3CRITICAL
What is CVE-2026-85520?
The Google Merchant Center Feed module for PrestaShop has a security flaw that permits unauthenticated attackers to exploit the feed.php endpoint. By manipulating request parameters, an attacker can dictate the output file name, path, extension, and content, which leads to a lack of proper input validation and authentication. This vulnerability allows the execution of arbitrary PHP code, culminating in potential remote code execution (RCE). It is essential for users to upgrade to version 2.3.9 or higher to mitigate this security risk.
Affected Version(s)
Google Merchant Center Feed 1.9.1 <= 2.3.8
