
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12975 is a missing authorization vulnerability in the CTX Feed – WooCommerce Product Feed Manager plugin for WordPress, allowing authenticated attackers to install arbitrary plugins and potentially achieve remote code execution. It affects all versions of the plugin up to and including 6.6.11. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).
The root cause is a missing capability check (CWE-862) on the woo_feed_plugin_installing() function within the CTX Feed plugin. Because no authorization check is enforced, any authenticated user with Shop Manager-level access or higher can invoke this function to install arbitrary WordPress plugins from the plugin repository or external sources. This plugin installation capability can then be chained to deploy a malicious plugin that executes attacker-controlled PHP code on the server (Red Hat CVE, Wordfence).
Successful exploitation allows an attacker with Shop Manager privileges to install arbitrary plugins, which can be leveraged to achieve full remote code execution on the WordPress host. This results in high confidentiality, integrity, and availability impact — an attacker could exfiltrate sensitive customer and order data, modify site content, establish persistent backdoors, or pivot to other systems on the same network (Red Hat CVE).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.245%, indicating a relatively low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authenticated access at the Shop Manager level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE, Wordfence).
woo_feed_plugin_installing() function, specifying an arbitrary plugin slug or URL as the installation target — bypassing any capability check.debug.log or server access logs showing unexpected POST requests to admin-ajax.php or admin endpoints invoking woo_feed_plugin_installing by Shop Manager accounts.wp-content/plugins/ not corresponding to legitimate installations; PHP files with obfuscated code or web shell patterns (e.g., eval(base64_decode(...))).wp_options table, active_plugins key) showing unfamiliar plugin entries.bash, curl, wget) after plugin activation.Users should update the CTX Feed – WooCommerce Product Feed Manager plugin to a version beyond 6.6.11 that includes a proper capability check on the woo_feed_plugin_installing() function. Until a patch is applied, site administrators should audit Shop Manager accounts and restrict that role to trusted users only. Additionally, consider using a WordPress security plugin (e.g., Wordfence) to monitor and block unauthorized plugin installation attempts (Wordfence, Red Hat CVE).
Wordfence included CVE-2025-12975 in their weekly WordPress vulnerability report for February 16–22, 2026, flagging it as a notable missing authorization issue in a widely used WooCommerce plugin (Wordfence). The vulnerability was also noted by RedPacketSecurity on Mastodon and tracked by threat intelligence platforms such as VulnDB and Offseq Radar, indicating moderate community awareness.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."