AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16611

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Product Feed PRO for WooCommerce plugin for WordPress, prior to version 13.5.7, lacks proper authorization checks on a REST read route, enabling unauthenticated users to access sensitive store feed configurations and enumerate product categories. This vulnerability could lead to exposure of critical business information and product details, making it a priority for e-commerce site administrators using this plugin to update to the latest version to mitigate potential data leaks.

CVE
CVE-2026-16611
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.