PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16611 AdTribes CVE debrief

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy. This vulnerability allows attackers to access sensitive information about a store's product feed configuration and taxonomy, potentially leading to further exploitation. Users of the plugin should verify their version and ensure it is updated to 13.5.7 or later to mitigate this vulnerability.

Vendor
AdTribes
Product
Product Feed PRO for WooCommerce
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-26
Advisory published
2026-08-15
Advisory updated
2026-08-26

Who should care

Users of the Product Feed PRO for WooCommerce by AdTribes WordPress plugin, administrators of affected systems, and security teams responsible for vulnerability management and monitoring.

Technical summary

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 is vulnerable to unauthorized access, allowing unauthenticated users to disclose feed configuration and enumerate product category taxonomy. The plugin's REST read route lacks proper authorization checks, enabling attackers to access and potentially exploit this information. To address this vulnerability, users should patch the plugin to version 13.5.7 or later and verify that REST API routes are properly secured.

Defensive priority

Patch and verify plugin version; restrict unauthorized access to REST API routes.

Recommended defensive actions

  • Patch the Product Feed PRO for WooCommerce by AdTribes WordPress plugin to version 13.5.7 or later.
  • Verify and restrict unauthorized access to REST API routes.
  • Monitor for unauthorized access attempts to feed configuration and product category taxonomy.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The evidence for this CVE is limited. The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy. Defenders should verify plugin version, REST API route access controls, and monitor for unauthorized access attempts to feed configuration and product category taxonomy.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16611 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16611

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16611 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16611

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.