CVE-2026-10026: CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already be authenticated to WordPress with Administrator-level access or higher. The issue is therefore most relevant where administrator accounts are compromised, shared, improperly granted, or controlled by untrusted users.
What access does successful exploitation provide?
A qualifying attacker can execute arbitrary PHP code on the server through the plugin's Feed Config field. The reported impact includes complete compromise of confidentiality, integrity, and availability.
Which installations are affected?
All CTX Feed Pro versions up to and including 7.6.12 are affected, according to the supplied vulnerability information.