Sceawere
Vulnerability Detail
CVE-2026-10026UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CTX Feed Pro Code Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 18h ago
- Vendor
- CTX
- Product
- CTX Feed Pro
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T05:16:36.503Z",
"pubdate": "2026-10-02T05:16:36.503Z",
"executiveSummary": "The CTX Feed Pro plugin for WordPress is susceptible to an authenticated arbitrary code execution vulnerability affecting all versions up to and including 7.6.12.\nThe vulnerability is classified as Code Injection, arising from improper neutralization of user-supplied data during the processing of configuration fields.\nThis flaw enables authenticated attackers possessing administrative privileges to execute arbitrary PHP code within the context of the web server, potentially leading to full site compromise.\nThe impact includes unauthorized access to system files, database manipulation, and the potential for establishing persistence or further lateral movement within the hosting environment.\nSuccessful exploitation requires the attacker to have already achieved Administrator-level access to the WordPress dashboard.\nThe vulnerability underscores the critical risk associated with the use of sensitive sink functions, such as eval(), when processing user-controlled input.",
"technicalDetails": "The vulnerability resides in the 'Feed Config' functionality of the CTX Feed Pro plugin, which fails to adequately sanitize or validate user input before passing it to an execution context.\nThe root cause is the direct passage of unsanitized input from the 'Feed Config' field into the PHP eval() function. The eval() function is a dangerous language construct that executes strings as PHP code; when utilized with user-controllable input, it creates a trivial vector for arbitrary code execution.\nExploitation is achieved through an authenticated session where an attacker with Administrator privileges navigates to the 'Feed Config' administrative interface. By injecting malicious PHP payloads into the configuration parameters, the attacker forces the server to evaluate the payload.\nThe attack flow proceeds as follows: 1) The attacker authenticates as an Administrator. 2) The attacker interacts with the 'Feed Config' settings page. 3) The attacker submits a specially crafted configuration string containing PHP code. 4) The plugin backend retrieves this string and passes it directly to the eval() function without preceding validation or sandboxing. 5) The server-side interpreter executes the injected payload, granting the attacker the same permissions as the web server process (e.g., www-data).\nThis vulnerability is classified as critical due to the direct execution of code in the server process. Because the payload runs with the privileges of the web user, the attacker can execute system-level commands, read or modify sensitive configuration files (such as wp-config.php), dump database content, or install backdoors.\nThe lack of input filtering and the dangerous usage of eval() represent a failure in secure coding practices. Even though the vulnerability is restricted to users with Administrator roles, the severity remains high because any compromised administrative account or insider threat can weaponize this feature to gain complete control over the underlying server infrastructure.\nThe scope of impact is comprehensive; once the initial code execution is established, the attacker can bypass WordPress security controls entirely, disable security plugins, or utilize the server for malicious outbound traffic, effectively rendering the site a node in a broader attack network."
}