CVE-2026-32443
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32443 is a Cross-Site Request Forgery (CSRF) vulnerability in the Product Feed PRO for WooCommerce WordPress plugin, developed by Josh Kohlbach. It affects all versions from n/a through 13.5.2 and allows unauthenticated attackers to perform unauthorized actions by tricking authenticated users into submitting crafted requests. The vulnerability was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate the origin of state-changing HTTP requests. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or shop manager, silently submits forged requests to the plugin's endpoints. This requires no privileges on the attacker's part but does require user interaction — specifically, the victim must be logged into the WordPress site and visit the attacker-controlled page. No public proof-of-concept exploit code has been identified at this time (Feedly, Patchstack).

Impact

Successful exploitation allows an attacker to modify product feed configurations and plugin settings without authentication, compromising data integrity on the affected WooCommerce store. Since the attack is performed in the context of an authenticated user, any action available to that user (e.g., altering product feed URLs, disabling feeds, or changing output settings) can be executed without their knowledge. Confidentiality and availability are not directly impacted, but manipulated product feeds could redirect traffic, corrupt feed data sent to shopping platforms (e.g., Google Shopping, Facebook), or disrupt e-commerce operations (Feedly).

Exploitability

No active in-the-wild exploitation has been reported for CVE-2026-32443, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at approximately 0.008%, indicating a very low probability of exploitation in the near term. No weaponized exploit kits or threat actor attribution have been identified. The attack requires user interaction, which limits opportunistic exploitation compared to fully unauthenticated vulnerabilities (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Product Feed PRO for WooCommerce plugin (version ≤ 13.5.2) using tools like WPScan or by inspecting publicly visible plugin metadata in page source.
  2. Craft malicious request: Analyze the plugin's admin-facing endpoints (e.g., settings update or feed management actions) to identify state-changing requests that lack CSRF token validation.
  3. Build a forged page: Create an HTML page containing a hidden form or JavaScript that automatically submits a POST request to the target WordPress site's vulnerable plugin endpoint with attacker-chosen parameters (e.g., modifying feed URLs or disabling feeds).
  4. Deliver to victim: Send the malicious page link to an authenticated WordPress administrator or shop manager via phishing email, social engineering, or by embedding it in a comment/forum post.
  5. Achieve unauthorized action: When the victim visits the page while logged into their WordPress site, the browser automatically submits the forged request with the victim's session cookies, causing the plugin to execute the attacker-specified action without the victim's knowledge (Feedly, Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to plugin admin endpoints (e.g., /wp-admin/admin-ajax.php or plugin-specific action URLs) from unusual referrer origins or with no referrer header.
  • Logs: WordPress audit logs (if enabled via a plugin like WP Activity Log) recording unexpected changes to product feed settings or configurations without corresponding administrator activity.
  • Network: HTTP requests to WordPress admin endpoints originating from external or unexpected referrer domains, particularly with no valid nonce values in the request body.
  • File System / Database: Unexpected modifications to product feed configurations in the WordPress database (wp_options table or plugin-specific tables) at unusual times or without a corresponding admin session.

Mitigation and workarounds

Users should upgrade the Product Feed PRO for WooCommerce plugin to version 13.5.3 or later, which contains the fix for this CSRF vulnerability. As a general workaround prior to patching, administrators can restrict access to the WordPress admin panel by IP allowlisting or by using a Web Application Firewall (WAF) rule to block cross-origin POST requests to admin endpoints. Ensuring that only trusted users have administrator or shop manager roles also reduces the attack surface (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14444HIGH7.5
  • wp-fusion
NoYesSep 07, 2026
CVE-2026-6431HIGH7.2
  • profile-builder
NoYesSep 07, 2026
CVE-2026-12757MEDIUM6.5
  • email-subscribers
NoYesSep 07, 2026
CVE-2026-8279MEDIUM5.3
  • learning-management-system
NoYesSep 07, 2026
CVE-2026-4945MEDIUM5.3
  • otter-blocks
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management