Skip to content
Threat Feed
high advisory

Authenticated Remote Code Execution in CTX Feed Pro WordPress Plugin

The CTX Feed Pro WordPress plugin contains a code injection vulnerability (CVE-2026-10026) allowing authenticated administrators to achieve remote code execution via insufficient input validation.

CVE search metadata

CVE search record: CVE-2026-10026. Severity: high. CVSS: 7.2. KEV: no. Product: CTX Feed Pro (<= 7.6.12). Brief: Authenticated Remote Code Execution in CTX Feed Pro WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ctx-feed-pro-code-injection/

The CTX Feed Pro plugin for WordPress (all versions up to and including 7.6.12) is vulnerable to a code injection attack. The vulnerability exists due to improper input validation within the 'Feed Config' functionality. Specifically, user-supplied input provided to the 'Feed Config' field is processed by the PHP eval() function without adequate sanitization or verification. An attacker who has obtained valid Administrator-level credentials can exploit this flaw to execute arbitrary PHP code on the underlying web server. This vulnerability allows for complete system compromise if the web server process runs with sufficient privileges. Given the requirement for Administrator-level access, this is primarily a risk for organizations where administrative accounts may be compromised through other means, such as credential theft or phishing.

Impact

Successful exploitation of this vulnerability allows authenticated attackers to execute arbitrary code on the web server hosting the WordPress instance. This can lead to full site takeover, data exfiltration, backdooring of the environment, and potentially lateral movement within the hosting network. The impact is critical for sites using the CTX Feed Pro plugin if administrative access is not strictly controlled or monitored.

Recommendation

  • Update the CTX Feed Pro plugin to a version beyond 7.6.12 as soon as a patch is made available by the vendor.
  • Implement the Principle of Least Privilege for WordPress administrative accounts to reduce the number of users capable of modifying sensitive feed configurations.
  • Audit WordPress administrative activity logs to identify suspicious modifications to plugin configuration settings.
  • Implement web application firewall (WAF) rules to detect and block suspicious input strings containing PHP-specific functions like 'eval()' in POST requests directed at plugin configuration endpoints.

Immediate actions

Inventory all WordPress installations and identify instances using CTX Feed Pro

IT Operations 24h

Mitigations

Upgrade CTX Feed Pro to the latest available version beyond 7.6.12

immediate IT Operations

CVE-2026-10026