OVERVIEW CVE-2026-3499 affects the Product Feed PRO for WooCommerce plugin by AdTribes (versions 13.4.6 through 13.5.2.1) and exploits insufficient nonce validation in multiple AJAX functions. The vulnerability allows unauthenticated attackers to perform unauthorized actions including feed migration, clearing custom-attribute caches, modifying feed file URLs, toggling legacy filter settings, and deleting duplicated feed posts through cross-site request forgery attacks. SEVERITY The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and user interaction. An attacker needs only to trick a site administrator into clicking a malicious link to execute the attack. The impact is severe, affecting confidentiality, integrity, and availability of feed data and plugin functionality. This represents a significant risk to WordPress sites using the affected plugin versions. EXPLOITATION STATUS There is no evidence of active exploitation at this time. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on the Hot List, indicating minimal community attention and no publicly available exploit code. However, the FAUCET risk score of 52.0/100 suggests moderate concern, and organizations should implement patches promptly to prevent future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Jkohlbach | Product Feed PRO For WooCommerce By AdTribes – Product Feeds For WooCommerce | >= 13.4.6, <= 13.5.2.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.