CVE-2026-16611
7.5AdTribes · Product Feed PRO for WooCommerce
An authorization bypass vulnerability in the Product Feed PRO for WooCommerce plugin allows unauthenticated users to disclose sensitive store configuration and product category data.
Executive summary
An unauthenticated authorization bypass in the Product Feed PRO for WooCommerce plugin allows attackers to extract sensitive store configuration and product taxonomy data.
Vulnerability
The plugin fails to perform necessary capability or authorization checks on specific REST read routes. This oversight allows unauthenticated attackers to query the API to disclose feed configurations, rules, filters, and field mappings.
Business impact
With a CVSS score of 7.5, this high-severity vulnerability exposes critical business intelligence. Unauthorized access to feed configurations and product category taxonomy can facilitate competitive intelligence gathering, assist in crafting targeted phishing campaigns, or expose internal business logic, all of which threaten the confidentiality of the e-commerce store.
Remediation
Immediate Action: Update the Product Feed PRO for WooCommerce plugin to version 13.5.7 or later immediately.
Proactive Monitoring: Review REST API access logs for unauthorized requests targeting the plugin endpoints.
Compensating Controls: If an immediate update is not feasible, restrict access to the WordPress REST API for unauthorized users via security plugins or server-side configuration.
Exploitation status
Public Exploit Available: Yes, public exploit references are available.
Analyst recommendation
The exposure of sensitive business configuration data is a significant concern for e-commerce operators. We strongly recommend upgrading to version 13.5.7 or later as the primary method to mitigate this information disclosure risk.