CVE-2026-73383: WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerability
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CTX Feed pluginto a version that resolves this vulnerability.Fixed in 6.6.48
Event History
Frequently Asked Questions
Who needs to be able to access the site for this issue to be exploited?
The affected component is the WordPress CTX Feed plugin in versions 6.6.47 and earlier. Exploitation requires shop manager privileges, so unauthenticated users and lower-privileged accounts are not identified as able to exploit it by the provided data.
What are the practical exploitation prerequisites?
An attacker needs a shop manager-level WordPress account and network access. No user interaction is required, and the issue has low attack complexity.
What is the expected impact if exploitation succeeds?
The vulnerability can allow arbitrary file download through path traversal. The stated impact is confidentiality only; integrity and availability impacts are not indicated.