Impact
The CTX Feed Pro plugin for WordPress contains a code injection flaw in all releases up to 7.6.12. The flaw arises because the Feed Config field is sent directly to PHP's eval() without any sanitization. An attacker who can authenticate as an administrator or higher can submit crafted input that causes eval to execute arbitrary PHP code, giving the attacker full control over the web server and any data it stores.
Affected Systems
WordPress sites that have the CTX Feed Pro plugin installed, with any version that is 7.6.12 or earlier, are affected. The vendor responsible is CTX.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and while a publicly available EPSS score is not provided, the absence of listing in the CISA KEV catalog suggests no widespread exploitation yet. The vulnerability requires the attacker to have administrator-level access, so the attack vector is authenticated via WordPress login. Once exploitation occurs, the attacker can run arbitrary PHP code, potentially exfiltrating data, installing backdoors, or disrupting services.
OpenCVE Enrichment