CVE-2026-16611: Unknown Product Feed Pro For Woocommerce By Adtribes

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.

Affected products

  • Unknown Product Feed Pro For Woocommerce By Adtribes: before 13.5.7 (fixed in 13.5.7)

Published 2026-08-15. Last modified 2026-08-26.