
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32443 is a Cross-Site Request Forgery (CSRF) vulnerability in the Product Feed PRO for WooCommerce WordPress plugin, developed by Josh Kohlbach. It affects all versions from n/a through 13.5.2 and allows unauthenticated attackers to perform unauthorized actions by tricking authenticated users into submitting crafted requests. The vulnerability was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate the origin of state-changing HTTP requests. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or shop manager, silently submits forged requests to the plugin's endpoints. This requires no privileges on the attacker's part but does require user interaction — specifically, the victim must be logged into the WordPress site and visit the attacker-controlled page. No public proof-of-concept exploit code has been identified at this time (Feedly, Patchstack).
Successful exploitation allows an attacker to modify product feed configurations and plugin settings without authentication, compromising data integrity on the affected WooCommerce store. Since the attack is performed in the context of an authenticated user, any action available to that user (e.g., altering product feed URLs, disabling feeds, or changing output settings) can be executed without their knowledge. Confidentiality and availability are not directly impacted, but manipulated product feeds could redirect traffic, corrupt feed data sent to shopping platforms (e.g., Google Shopping, Facebook), or disrupt e-commerce operations (Feedly).
No active in-the-wild exploitation has been reported for CVE-2026-32443, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at approximately 0.008%, indicating a very low probability of exploitation in the near term. No weaponized exploit kits or threat actor attribution have been identified. The attack requires user interaction, which limits opportunistic exploitation compared to fully unauthenticated vulnerabilities (Feedly).
/wp-admin/admin-ajax.php or plugin-specific action URLs) from unusual referrer origins or with no referrer header.wp_options table or plugin-specific tables) at unusual times or without a corresponding admin session.Users should upgrade the Product Feed PRO for WooCommerce plugin to version 13.5.3 or later, which contains the fix for this CSRF vulnerability. As a general workaround prior to patching, administrators can restrict access to the WordPress admin panel by IP allowlisting or by using a Web Application Firewall (WAF) rule to block cross-origin POST requests to admin endpoints. Ensuring that only trusted users have administrator or shop manager roles also reduces the attack surface (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."