PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3499 jkohlbach CVE debrief

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on several functions. Una auth users can trigger feed migration, clear custom-attribute transient caches, rewrite feed file URLs to lowercase, toggle legacy filter and rule settings, and delete duplicated feed posts via a forged request. The vulnerability exists in versions 13.4.6 through 13.5.2.1 of the Product Feed PRO for WooCommerce plugin.

Vendor
jkohlbach
Product
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the Product Feed PRO for WooCommerce plugin, especially those with untrusted users accessing the site, should apply the necessary updates to prevent exploitation. Site administrators and security teams should review the vulnerability details and assess their exposure to potential attacks.

Technical summary

The vulnerability exists in versions 13.4.6 through 13.5.2.1 of the Product Feed PRO for WooCommerce plugin. The issue arises from inadequate nonce validation in the ajax_migrate_to_custom_post_type, ajax_adt_clear_custom_attributes_product_meta_keys, ajax_update_file_url_to_lower_case, ajax_use_legacy_filters_and_rules, and ajax_fix_duplicate_feed functions. This allows unauthenticated attackers to perform various actions by tricking site administrators into clicking on a link.

Defensive priority

High priority due to the high CVSS score of 8.8 and the potential for unauthenticated attacks.

Recommended defensive actions

  • Update the Product Feed PRO for WooCommerce plugin to a version that fixes the CSRF vulnerability.
  • Implement additional monitoring for suspicious requests to the affected functions.
  • Educate site administrators on the risks of clicking on unverified links.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-04-08T02:16:04.237Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3499 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3499

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3499 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3499

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.