Remote Code Execution Vulnerability in CTX Feed Plugin for WooCommerce by WebAppick
CVE-2026-66709

9.1CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-66709?

The CTX Feed plugin for WooCommerce is susceptible to a remote code execution vulnerability in versions 6.6.42 and earlier. This flaw allows attackers to execute arbitrary code on affected installations with proper exploitation techniques. Users of the plugin should upgrade to the latest version to safeguard against potential attacks, ensuring their e-commerce platform's integrity and security.

Affected Version(s)

CTX Feed <= 6.6.42

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.