CVE-2025-12975
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows attackers with Shop Manager-level access or higher to install any plugin on a WordPress site, potentially leading to full control over the site through remote code execution. The issue arises from a lack of security checks in a specific function of the WooCommerce Product Feed Manager plugin, making it easy for these authenticated users to exploit the flaw.
Technical Description
The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to install arbitrary plugins which can be leveraged to achieve remote code execution.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 19, 2026
about 2 months ago
Last Modified
Feb 19, 2026
about 2 months ago