PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3499 jkohlbach CVE debrief

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on several functions. Una auth users can trigger feed migration, clear custom-attribute transient caches, rewrite feed file URLs to lowercase, toggle legacy filter and rule settings, and delete duplicated feed posts via a forged request. The vulnerability exists in versions 13.4.6 through 13.5.2.1 of the Product Feed PRO for WooCommerce plugin.

Vendor
jkohlbach
Product
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the Product Feed PRO for WooCommerce plugin, especially those with untrusted users accessing the site, should apply the necessary updates to prevent exploitation. Site administrators and security teams should review the vulnerability details and assess their exposure to potential attacks.

Technical summary

The vulnerability exists in versions 13.4.6 through 13.5.2.1 of the Product Feed PRO for WooCommerce plugin. The issue arises from inadequate nonce validation in the ajax_migrate_to_custom_post_type, ajax_adt_clear_custom_attributes_product_meta_keys, ajax_update_file_url_to_lower_case, ajax_use_legacy_filters_and_rules, and ajax_fix_duplicate_feed functions. This allows unauthenticated attackers to perform various actions by tricking site administrators into clicking on a link.

Defensive priority

High priority due to the high CVSS score of 8.8 and the potential for unauthenticated attacks.

Recommended defensive actions

  • Update the Product Feed PRO for WooCommerce plugin to a version that fixes the CSRF vulnerability.
  • Implement additional monitoring for suspicious requests to the affected functions.
  • Educate site administrators on the risks of clicking on unverified links.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-04-08T02:16:04.237Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T02:16:04.237Z and has not been modified since then. The NVD entry is currently Deferred.