CVE-2026-32443: WordPress Product Feed PRO for WooCommerce plugin <= 13.5.2 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forgery.This issue affects Product Feed PRO for WooCommerce: from n/a through <= 13.5.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32443?
CVE-2026-32443 is classified as a Cross-Site Request Forgery (CSRF) vulnerability in the Product Feed PRO for WooCommerce plugin.
How does CVE-2026-32443 affect users?
CVE-2026-32443 can allow attackers to perform unauthorized actions on behalf of authenticated users, potentially compromising user data.
How do I fix CVE-2026-32443?
To mitigate CVE-2026-32443, users should update the Product Feed PRO for WooCommerce plugin to the latest version beyond 13.5.2.
Is CVE-2026-32443 specific to certain versions of the plugin?
Yes, CVE-2026-32443 affects versions of the Product Feed PRO for WooCommerce plugin up to and including 13.5.2.
What steps can I take to prevent CVE-2026-32443?
Implement security best practices such as keeping plugins updated and utilizing security plugins to safeguard against CSRF vulnerabilities like CVE-2026-32443.