
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0926 is a Local File Inclusion (LFI) vulnerability in the Prodigy Commerce plugin for WordPress, affecting all versions up to and including 3.3.0. The flaw exists in the parameters[template_name] parameter and allows unauthenticated attackers to include, read, or execute arbitrary files on the server, including PHP code. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Wordfence).
The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program — 'PHP Remote File Inclusion'), with a secondary estimate of CWE-22 (Path Traversal). The vulnerability arises because the plugin fails to properly sanitize or restrict the parameters[template_name] parameter before using it in a PHP file inclusion operation, allowing an attacker to supply arbitrary file paths. No authentication is required, and exploitation can be achieved via a crafted HTTP request. A nuclei detection template has been developed and merged into the ProjectDiscovery nuclei-templates repository, and a public exploit repository (github.com/diamorphine666/CVE-2026-0926-exploit) has appeared (Feedly, Nuclei Templates).
Successful exploitation allows unauthenticated remote attackers to read arbitrary files from the server (e.g., wp-config.php containing database credentials), execute arbitrary PHP code, and achieve full remote code execution. This can result in complete compromise of the WordPress installation and underlying server, exposure of sensitive data, and potential lateral movement within the hosting environment. The ability to leverage uploaded image or other "safe" file types as PHP execution vectors makes this particularly dangerous in shared hosting scenarios (Feedly).
A public exploit repository for CVE-2026-0926 has been published on GitHub (diamorphine666/CVE-2026-0926-exploit), and the vulnerability has been indexed on Sploitus (EDB-ID:52598), indicating weaponized exploit code is publicly available (Feedly, Sploitus). Nuclei detection templates have been merged into the ProjectDiscovery repository, enabling automated scanning. The EPSS score is approximately 0.231%, and no CISA KEV catalog listing has been identified. No specific threat actor attribution or confirmed in-the-wild exploitation has been reported at this time (Feedly).
parameters[template_name] parameter in HTTP requests.parameters[template_name] value pointing to a sensitive file (e.g., ../../../../wp-config.php) or a previously uploaded PHP-containing file (e.g., a crafted image).parameters[template_name] values containing path traversal sequences (e.g., ../, ..%2F) or references to system files such as /etc/passwd or wp-config.php.template_name values; HTTP 200 responses to requests containing traversal patterns.wp-content/uploads/); newly created files with .php extensions in non-standard locations.bash, curl, wget, python) following requests to the plugin endpoint.wp-config.php contents or database credential exposure reflected in outbound database connections from unexpected hosts (Feedly).Update the Prodigy Commerce plugin to a version newer than 3.3.0 as soon as a patched release is available. If no patch is available, immediately deactivate and remove the plugin from the WordPress installation. As a network-level control, restrict direct HTTP access to WordPress installations where possible, and implement a Web Application Firewall (WAF) rule to block requests containing path traversal sequences in the parameters[template_name] parameter. Monitor server and access logs for suspicious file inclusion attempts targeting the plugin (Feedly, Wordfence).
Wordfence included CVE-2026-0926 in its weekly WordPress vulnerability report for February 16–22, 2026, highlighting it as a critical unauthenticated LFI issue (Wordfence). The vulnerability received attention on social media platforms including Mastodon and Bluesky, and was covered in cybersecurity news digests. The ProjectDiscovery community responded quickly by developing and merging multiple nuclei detection templates for automated scanning (Nuclei Templates). Qualys also published detection coverage for the vulnerability in its March 2026 application security detections update (Qualys).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."