Product Feed PRO for WooCommerce by AdTribes Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Product Feed PRO for WooCommerce by AdTribes plugin, specifically in versions 13.4.6 to 13.5.2.1. The vulnerability arises from inadequate nonce validation in several AJAX functions, allowing unauthenticated attackers to manipulate feed migration, clear custom attribute caches, modify feed file URLs, change legacy filter settings, and delete duplicate feed posts. Exploitation requires tricking a site administrator into clicking a link.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in feed management and post duplication, potentially disrupting the site's product feed functionality.

Remediation

Users are advised to update the plugin to version 13.5.2.2 or a newer patched version.

Added: Apr 8, 2026, 2:18 AM
Updated: Apr 8, 2026, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
7.0
remediation
7.7
relevance
5.5
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.