PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16611 AdTribes CVE debrief

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy. This vulnerability allows attackers to access sensitive information about a store's product feed configuration and taxonomy, potentially leading to further exploitation. Users of the plugin should verify their version and ensure it is updated to 13.5.7 or later to mitigate this vulnerability.

Vendor
AdTribes
Product
Product Feed PRO for WooCommerce
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Users of the Product Feed PRO for WooCommerce by AdTribes WordPress plugin, administrators of affected systems, and security teams responsible for vulnerability management and monitoring.

Technical summary

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 is vulnerable to unauthorized access, allowing unauthenticated users to disclose feed configuration and enumerate product category taxonomy. The plugin's REST read route lacks proper authorization checks, enabling attackers to access and potentially exploit this information. To address this vulnerability, users should patch the plugin to version 13.5.7 or later and verify that REST API routes are properly secured.

Defensive priority

Patch and verify plugin version; restrict unauthorized access to REST API routes.

Recommended defensive actions

  • Patch the Product Feed PRO for WooCommerce by AdTribes WordPress plugin to version 13.5.7 or later.
  • Verify and restrict unauthorized access to REST API routes.
  • Monitor for unauthorized access attempts to feed configuration and product category taxonomy.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The evidence for this CVE is limited. The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy. Defenders should verify plugin version, REST API route access controls, and monitor for unauthorized access attempts to feed configuration and product category taxonomy.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:17:08.380Z and has not been modified since then.