{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ctx-feed-pro--7.6.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:web:ctx_feed_pro:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-10026"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CTX Feed Pro (\u003c= 7.6.12)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","code-injection","cve"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe CTX Feed Pro plugin for WordPress (all versions up to and including 7.6.12) is vulnerable to a code injection attack. The vulnerability exists due to improper input validation within the 'Feed Config' functionality. Specifically, user-supplied input provided to the 'Feed Config' field is processed by the PHP eval() function without adequate sanitization or verification. An attacker who has obtained valid Administrator-level credentials can exploit this flaw to execute arbitrary PHP code on the underlying web server. This vulnerability allows for complete system compromise if the web server process runs with sufficient privileges. Given the requirement for Administrator-level access, this is primarily a risk for organizations where administrative accounts may be compromised through other means, such as credential theft or phishing.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows authenticated attackers to execute arbitrary code on the web server hosting the WordPress instance. This can lead to full site takeover, data exfiltration, backdooring of the environment, and potentially lateral movement within the hosting network. The impact is critical for sites using the CTX Feed Pro plugin if administrative access is not strictly controlled or monitored.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the CTX Feed Pro plugin to a version beyond 7.6.12 as soon as a patch is made available by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement the Principle of Least Privilege for WordPress administrative accounts to reduce the number of users capable of modifying sensitive feed configurations.\u003c/li\u003e\n\u003cli\u003eAudit WordPress administrative activity logs to identify suspicious modifications to plugin configuration settings.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block suspicious input strings containing PHP-specific functions like 'eval()' in POST requests directed at plugin configuration endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T06:22:43Z","date_published":"2026-10-02T06:22:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ctx-feed-pro-code-injection/","summary":"The CTX Feed Pro WordPress plugin contains a code injection vulnerability (CVE-2026-10026) allowing authenticated administrators to achieve remote code execution via insufficient input validation.","title":"Authenticated Remote Code Execution in CTX Feed Pro WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-ctx-feed-pro-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - CTX Feed Pro (\u003c= 7.6.12)","version":"https://jsonfeed.org/version/1.1"}