CVE-2025-12975
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12975 is a missing authorization vulnerability in the CTX Feed – WooCommerce Product Feed Manager plugin for WordPress, allowing authenticated attackers to install arbitrary plugins and potentially achieve remote code execution. It affects all versions of the plugin up to and including 6.6.11. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is a missing capability check (CWE-862) on the woo_feed_plugin_installing() function within the CTX Feed plugin. Because no authorization check is enforced, any authenticated user with Shop Manager-level access or higher can invoke this function to install arbitrary WordPress plugins from the plugin repository or external sources. This plugin installation capability can then be chained to deploy a malicious plugin that executes attacker-controlled PHP code on the server (Red Hat CVE, Wordfence).

Impact

Successful exploitation allows an attacker with Shop Manager privileges to install arbitrary plugins, which can be leveraged to achieve full remote code execution on the WordPress host. This results in high confidentiality, integrity, and availability impact — an attacker could exfiltrate sensitive customer and order data, modify site content, establish persistent backdoors, or pivot to other systems on the same network (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.245%, indicating a relatively low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authenticated access at the Shop Manager level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the CTX Feed – WooCommerce Product Feed Manager plugin at version 6.6.11 or earlier, using tools like WPScan or Shodan.
  2. Obtain credentials: Acquire Shop Manager-level (or higher) credentials through phishing, credential stuffing, or purchasing compromised accounts.
  3. Authenticate: Log in to the WordPress admin panel or WooCommerce backend with the obtained credentials.
  4. Invoke vulnerable function: Send a crafted authenticated HTTP request to trigger the woo_feed_plugin_installing() function, specifying an arbitrary plugin slug or URL as the installation target — bypassing any capability check.
  5. Install malicious plugin: Supply a malicious plugin (e.g., a web shell packaged as a WordPress plugin) as the installation target.
  6. Achieve RCE: Activate the installed malicious plugin via the WordPress admin interface, causing the server to execute attacker-controlled PHP code and enabling full server compromise (Red Hat CVE, Wordfence).

Indicators of compromise

  • Logs: WordPress debug.log or server access logs showing unexpected POST requests to admin-ajax.php or admin endpoints invoking woo_feed_plugin_installing by Shop Manager accounts.
  • File System: Unexpected new plugin directories under wp-content/plugins/ not corresponding to legitimate installations; PHP files with obfuscated code or web shell patterns (e.g., eval(base64_decode(...))).
  • Logs: WordPress plugin activation events in the database (wp_options table, active_plugins key) showing unfamiliar plugin entries.
  • Network: Outbound connections from the web server to unknown external hosts following plugin installation, potentially indicating reverse shell or C2 activity.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., bash, curl, wget) after plugin activation.

Mitigation and workarounds

Users should update the CTX Feed – WooCommerce Product Feed Manager plugin to a version beyond 6.6.11 that includes a proper capability check on the woo_feed_plugin_installing() function. Until a patch is applied, site administrators should audit Shop Manager accounts and restrict that role to trusted users only. Additionally, consider using a WordPress security plugin (e.g., Wordfence) to monitor and block unauthorized plugin installation attempts (Wordfence, Red Hat CVE).

Community reactions

Wordfence included CVE-2025-12975 in their weekly WordPress vulnerability report for February 16–22, 2026, flagging it as a notable missing authorization issue in a widely used WooCommerce plugin (Wordfence). The vulnerability was also noted by RedPacketSecurity on Mastodon and tracked by threat intelligence platforms such as VulnDB and Offseq Radar, indicating moderate community awareness.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15439MEDIUM6.5
  • gamipress
NoYesSep 11, 2026
CVE-2026-85116MEDIUM6.5
  • simple-cloudflare-turnstile
NoYesSep 11, 2026
CVE-2026-86809MEDIUM5.3
  • persian-elementor
NoYesSep 11, 2026
CVE-2026-86813MEDIUM4.8
  • metform
NoYesSep 11, 2026
CVE-2024-12145MEDIUM4.3
  • buddypress
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management