CVE-2026-0926: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0926 is a Local File Inclusion (LFI) vulnerability in the Prodigy Commerce plugin for WordPress, affecting all versions up to and including 3.3.0. The flaw exists in the parameters[template_name] parameter and allows unauthenticated attackers to include, read, or execute arbitrary files on the server, including PHP code. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Wordfence).

Technical details

The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program — 'PHP Remote File Inclusion'), with a secondary estimate of CWE-22 (Path Traversal). The vulnerability arises because the plugin fails to properly sanitize or restrict the parameters[template_name] parameter before using it in a PHP file inclusion operation, allowing an attacker to supply arbitrary file paths. No authentication is required, and exploitation can be achieved via a crafted HTTP request. A nuclei detection template has been developed and merged into the ProjectDiscovery nuclei-templates repository, and a public exploit repository (github.com/diamorphine666/CVE-2026-0926-exploit) has appeared (Feedly, Nuclei Templates).

Impact

Successful exploitation allows unauthenticated remote attackers to read arbitrary files from the server (e.g., wp-config.php containing database credentials), execute arbitrary PHP code, and achieve full remote code execution. This can result in complete compromise of the WordPress installation and underlying server, exposure of sensitive data, and potential lateral movement within the hosting environment. The ability to leverage uploaded image or other "safe" file types as PHP execution vectors makes this particularly dangerous in shared hosting scenarios (Feedly).

Exploitability

A public exploit repository for CVE-2026-0926 has been published on GitHub (diamorphine666/CVE-2026-0926-exploit), and the vulnerability has been indexed on Sploitus (EDB-ID:52598), indicating weaponized exploit code is publicly available (Feedly, Sploitus). Nuclei detection templates have been merged into the ProjectDiscovery repository, enabling automated scanning. The EPSS score is approximately 0.231%, and no CISA KEV catalog listing has been identified. No specific threat actor attribution or confirmed in-the-wild exploitation has been reported at this time (Feedly).

Exploitation steps

  1. Reconnaissance: Use tools like WPScan, Shodan, or Censys to identify WordPress sites running the Prodigy Commerce plugin version ≤ 3.3.0.
  2. Identify vulnerable endpoint: Locate the plugin's endpoint or AJAX action that processes the parameters[template_name] parameter in HTTP requests.
  3. Craft malicious request: Send an unauthenticated HTTP POST or GET request to the vulnerable endpoint with a manipulated parameters[template_name] value pointing to a sensitive file (e.g., ../../../../wp-config.php) or a previously uploaded PHP-containing file (e.g., a crafted image).
  4. Read sensitive files: If targeting file disclosure, the server will return the contents of the specified file, exposing credentials or configuration data.
  5. Achieve code execution: Upload a file containing PHP code (e.g., via WordPress media upload or another vector), then include it via the LFI parameter to execute arbitrary PHP commands on the server, enabling a web shell or reverse shell (Feedly, GitHub Exploit).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress endpoints with parameters[template_name] values containing path traversal sequences (e.g., ../, ..%2F) or references to system files such as /etc/passwd or wp-config.php.
  • Logs: WordPress or web server access logs showing repeated requests to Prodigy Commerce plugin endpoints with encoded or suspicious template_name values; HTTP 200 responses to requests containing traversal patterns.
  • File System: Unexpected PHP files or web shells in the WordPress uploads directory (wp-content/uploads/); newly created files with .php extensions in non-standard locations.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget, python) following requests to the plugin endpoint.
  • Application: Unauthorized access to wp-config.php contents or database credential exposure reflected in outbound database connections from unexpected hosts (Feedly).

Mitigation and workarounds

Update the Prodigy Commerce plugin to a version newer than 3.3.0 as soon as a patched release is available. If no patch is available, immediately deactivate and remove the plugin from the WordPress installation. As a network-level control, restrict direct HTTP access to WordPress installations where possible, and implement a Web Application Firewall (WAF) rule to block requests containing path traversal sequences in the parameters[template_name] parameter. Monitor server and access logs for suspicious file inclusion attempts targeting the plugin (Feedly, Wordfence).

Community reactions

Wordfence included CVE-2026-0926 in its weekly WordPress vulnerability report for February 16–22, 2026, highlighting it as a critical unauthenticated LFI issue (Wordfence). The vulnerability received attention on social media platforms including Mastodon and Bluesky, and was covered in cybersecurity news digests. The ProjectDiscovery community responded quickly by developing and merging multiple nuclei detection templates for automated scanning (Nuclei Templates). Qualys also published detection coverage for the vulnerability in its March 2026 application security detections update (Qualys).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management