CVE-2026-85520: critical vulnerability in MyPresta Google Merchant Center Feed
Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module
Published
70Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.3epss 1.0%
from disclosure to weapon0 days
Published on NVDSep 29
1st PoCSep 29
VulnCheckSep 29
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE).
This issue was fixed in version 2.3.9.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Affected products
MyPresta · Google Merchant Center Feedpublic PoCs found — 2
githubgithub.com/murrez/CVE-2026-85520★ 0vulncheckvulncheck.com/xdb/a4234885520aunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.