What is CVE-2026-16611?
CVE-2026-16611 is due to a missing authorization check in the Product Feed PRO for WooCommerce plugin by AdTribes. It allows unauthenticated users to access a REST read route and disclose the store's feed configuration, including rules, filters, field mapping, and to enumerate full product categories. Versions before 13.5.7 are affected, so updating immediately is recommended.
Azərbaycanca: CVE-2026-16611, AdTribes-in WooCommerce üçün Product Feed PRO pluginində avtorizasiya yoxlamasının olmaması ilə bağlıdır. Bu boşluq autentifikasiya olunmamış istifadəçilərə REST route vasitəsilə mağazanın feed konfiqurasiyasını (qaydalar, filtrler, field mapping) və bütün məhsul kateqoriyalarını əldə etməyə imkan verir. Pluginin 13.5.7 versiyasından əvvəlki versiyaları təsirlənir, ona görə də dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What data can be accessed from an affected store through CVE-2026-16611?
This vulnerability allows unauthenticated users to access the store's feed configuration, including rules, filters, field mapping, and to enumerate full product categories via a REST route.
To which version should the Product Feed PRO plugin be updated to protect against CVE-2026-16611?
Versions before 13.5.7 are affected, so updating to at least version 13.5.7 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.