AdTribes Product Feed PRO
cpe:2.3:a:adtribes:product_feed_pro_for_woocommerce:*:*:*:*:wordpress:*:*
- >= 13.4.6, <= 13.5.2.1
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Product Feed PRO for WooCommerce by AdTribes plugin, specifically in versions 13.4.6 to 13.5.2.1. The vulnerability arises from inadequate nonce validation in several AJAX functions, allowing unauthenticated attackers to manipulate feed migration, clear custom attribute caches, modify feed file URLs, change legacy filter settings, and delete duplicate feed posts. Exploitation requires tricking a site administrator into clicking a link.
Exploitation of this vulnerability could lead to unauthorized changes in feed management and post duplication, potentially disrupting the site's product feed functionality.
Users are advised to update the plugin to version 13.5.2.2 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.