7.5
CVE-2026-16611
- EPSS 0.26%
- Veröffentlicht 15.08.2026 06:00:14
- Zuletzt bearbeitet 26.08.2026 16:30:52
- Erkennungen
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
Product Feed PRO for WooCommerce <= 13.5.6 - Unauthenticated Information Exposure
The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.
Mögliche Gegenmaßnahme
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce: Update to version 13.5.7, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUnknown
≫
Produkt
Product Feed PRO for WooCommerce by AdTribes
Default Statusunaffected
Version
0
Version <
13.5.7
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
Version
*-13.5.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.174 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://wpscan.com/vulnerability/87fe63af-5a43-4812-88ce-568b1cc1598f/
https://www.wordfence.com/threat-intel/vulnerabilities/id/6cf9256c-51a1-47d5-8be5-c9697dce2ae3