CVE-2026-16611

Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.


We have discovered 3,823 live websites that are affected by CVE-2026-16611.

Run a Free Instant Scan




Affected Software

Product  Woo Product Feed Pro
Category Wordpress Plugins
Vulnerable Domains3,823 live websites (100% of Woo Product Feed Pro install base)
Vulnerable Versions
  • from 0 through 13.5.7
Vulnerable Versions Count153 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Aug 15, 2026
  • Updated - Aug 17, 2026

Credits

  • Shivamani Vastrala (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16611
United States634 websites



Poland261 websites
Germany231 websites
Spain211 websites
Italy189 websites
Vietnam170 websites
France162 websites
Romania147 websites
GB137 websites
Ukraine107 websites

Website Distribution by TLD

Number of websites using CVE-2026-16611
.com1,290 websites
.pl193 websites
.it130 websites
.co.uk103 websites
.nl97 websites
.com.au94 websites
.es92 websites
.de91 websites
.dk76 websites
.cz69 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16611

Top websites that are affected by CVE-2026-16611. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
******.**.il United States**,***
*********.coffee United States**,***
*********.com United States***,***
**************.**.za South Africa***,***
*****.dk Denmark***,***
***************.nl Netherlands***,***
*************.pl Poland***,***
*********.sk Slovakia***,***
***********.es Spain***,***
See full domain list

FAQ

CVE-2026-16611 is Exposure of Sensitive Information to an Unauthorized Actor in Woo Product Feed Pro
A total of 3,823 websites have been identified as vulnerable to CVE-2026-16611, based on global website indexing conducted by WebTechSurvey.
The Woo Product Feed Pro is affected by the CVE-2026-16611 vulnerability.
Woo Product Feed Pro versions up to 13.5.7 are vulnerable to CVE-2026-16611.
CVE-2026-16611 is resolved in version 13.5.7 of Woo Product Feed Pro.