CVE-2026-103349: WordPress Product Feed PRO for WooCommerce plugin <= 13.5.7 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rymera Web Co Product Feed PRO for WooCommerceto a version that resolves this vulnerability.Fixed in 13.5.8
Event History
Frequently Asked Questions
Who can exploit this issue?
The listed CVSS vector requires high privileges (PR:H) and does not require user interaction. This indicates exploitation requires an attacker with a high-privilege account or equivalent access.
Which plugin versions are affected?
Product Feed PRO for WooCommerce versions through 13.5.7 are affected. The available data does not identify a fixed version.
What is the potential impact if exploited?
The vulnerability is rated high severity with a CVSS score of 7.2. Its vector indicates potential high impact to confidentiality, integrity, and availability.