Junglewise Threat Intelligence

CVE-2026-3499: AdTribes Product Feed PRO for WooCommerce CSRF in AJAX functions

CVE-2026-3499 · Severity: high · CVSS 8.8 · Published 2026-04-08

Executive brief

The Product Feed PRO plugin for WooCommerce, which helps online stores sync product data with marketing channels, is vulnerable to a security flaw that could allow an attacker to hijack administrative actions. By tricking a site administrator into clicking a malicious link, an attacker can remotely trigger data migrations, clear caches, or delete product feed configurations. This could lead to significant disruptions in marketing operations and unauthorized changes to how product data is handled.

Technical details

The Product Feed PRO for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on several AJAX functions, including ajax_migrate_to_custom_post_type and ajax_fix_duplicate_feed. An unauthenticated attacker can exploit this by inducing a logged-in administrator to interact with a malicious link or site. Successful exploitation allows the attacker to trigger feed migrations, clear custom-attribute caches, modify feed file URLs, toggle legacy settings, and delete feed posts. The vulnerability is present in versions 13.4.6 through 13.5.2.1 and has been addressed in subsequent updates.

Affected products

  • AdTribes Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce 13.4.6 - 13.5.2.1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References