CVE-2026-16611

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-15 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-16611

Mitre link : CVE-2026-16611

CVE.ORG link : CVE-2026-16611


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor