CVE-2026-66709: WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CTX Feed Pluginto a version that resolves this vulnerability.Fixed in 6.6.43 - Compensating control
If immediate upgrading is not possible, restrict access to the WordPress admin/management interface (and the WordPress site) to trusted IPs only until the CTX Feed plugin is updated to version 6.6.43 or later.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66709?
CVE-2026-66709 has a critical severity rating of 9.1.
How do I fix CVE-2026-66709?
To mitigate CVE-2026-66709, you should update the CTX Feed plugin to version 6.6.43 or later.
What type of vulnerability is CVE-2026-66709?
CVE-2026-66709 is a Remote Code Execution (RCE) vulnerability that allows unauthorized code execution.
Who is affected by CVE-2026-66709?
CVE-2026-66709 affects users of the CTX Feed plugin for WordPress, specifically versions 6.6.42 and below.
What can attackers do with CVE-2026-66709?
Attackers exploiting CVE-2026-66709 can execute arbitrary code on the server with shop manager privileges.