Executive brief
CTX Feed is a popular WordPress plugin for managing WooCommerce product feeds. A remote code execution vulnerability in versions 6.6.42 and earlier allows authenticated shop managers to inject and execute arbitrary commands on the server, potentially compromising the entire website and any data stored within it.
Technical details
This is a code injection vulnerability (classified as OWASP A3: Injection) in the CTX Feed WordPress plugin that affects versions up to 6.6.42. The vulnerability requires shop manager-level privileges to exploit, allowing an attacker with these credentials to inject malicious commands that execute remotely on the web server. The attack is network-reachable and does not require additional user interaction beyond authentication. Successful exploitation enables complete server compromise and arbitrary command execution. The vulnerability has been patched in version 6.6.43 and later.
Affected products
- WebAppick CTX Feed <= 6.6.42
Timeline
- 2026-08-04: disclosed
- 2026-08-04: patched: Patched in version 6.6.43