Description
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
Published: 2026-08-18
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an arbitrary file download flaw in the WordPress CTX Feed plugin versions 6.6.47 and earlier. An attacker can send a crafted request to the plugin’s download endpoint, causing the plugin to serve any file located on the web server. This flaw corresponds to CWE‑22. The result is that sensitive files such as configuration data, WordPress core files, or source code can be exposed, leading to data loss and possibly providing material for further attacks.

Affected Systems

The vulnerability affects the WebAppick CTX Feed plugin for WordPress. All installations of the plugin with a version number of 6.6.47 or earlier are vulnerable. The issue is resolved in version 6.6.48 and later.

Risk and Exploitability

The CVSS score of 4.9 classifies the flaw as moderate. EPSS was not provided and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a crafted request to the plugin’s unauthorized download endpoint, which may be reachable without authentication. No elevated privileges are required for exploitation, but the attacker can potentially read any file on the server, increasing the risk of data leakage.

Generated by OpenCVE AI on August 18, 2026 at 16:51 UTC.

Remediation

Vendor Solution

Update the WordPress CTX Feed plugin to the latest available version (at least 6.6.48).


OpenCVE Recommended Actions

  • Update the CTX Feed plugin to version 6.6.48 or newer.
  • If the plugin is no longer required, delete or deactivate it to close the exploited code path.
  • Restrict file system permissions for plugin directories to the minimum required and monitor for suspicious download activity.

Generated by OpenCVE AI on August 18, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Webappick
Webappick ctx Feed
Wordpress
Wordpress wordpress
Vendors & Products Webappick
Webappick ctx Feed
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
Title WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Webappick Ctx Feed
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:39:14.588Z

Reserved: 2026-08-12T14:09:17.491Z

Link: CVE-2026-73383

cve-icon Vulnrichment

Updated: 2026-08-18T14:39:11.529Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:06.403

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T18:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')