
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39434 is a PHP Object Injection vulnerability in the CTX Feed plugin (webappick-product-feed-for-woocommerce) for WordPress, affecting versions 6.6.26 and earlier. The flaw allows authenticated attackers with Shop Manager-level privileges to inject malicious PHP objects, potentially enabling code execution, SQL injection, path traversal, or denial of service if a suitable POP (Property-Oriented Programming) chain exists. It was reported by researcher "daroo" on February 26, 2026, disclosed by Patchstack on April 7, 2026, and assigned a CVSS v3.1 base score of 7.2 (High) (Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), where user-supplied input is passed to PHP's unserialize() function (or equivalent) without adequate validation, allowing an attacker to instantiate arbitrary PHP objects (Patchstack). Exploitation requires the attacker to hold Shop Manager privileges on the WordPress/WooCommerce installation, limiting the attack surface to authenticated users. The actual impact depends on the presence of a usable POP chain within the WordPress environment — if one exists, the attacker can escalate the injection into remote code execution, SQL injection, or file path traversal. The attack vector is network-based with low complexity and no user interaction required beyond authentication.
Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. Depending on available POP chains in the environment, an attacker could achieve remote code execution, access or exfiltrate sensitive data (including WooCommerce customer and order data), manipulate the database, or cause a denial of service. Lateral movement to the underlying server or connected systems is possible if code execution is achieved (Patchstack).
/wp-login.php)./wp-admin/admin.php?page=webappick* or similar) containing serialized PHP data patterns (e.g., O:<number>: strings in request bodies.wp_options or WooCommerce tables; unexpected admin user accounts created after the attack window.apache2, nginx, php-fpm) such as bash, curl, wget, or python; outbound network connections from the web server to unknown external IPs.Update the CTX Feed plugin to version 6.6.27 or later, which contains the fix for this vulnerability (Patchstack). Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. As an interim measure, restrict Shop Manager account access to trusted users only and enforce strong, unique passwords with multi-factor authentication. If the plugin cannot be updated immediately, consider temporarily deactivating it to eliminate the attack surface.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for April 6–12, 2026, and Sucuri referenced it in their April 2026 vulnerability patch roundup, indicating broad coverage within the WordPress security community (Wordfence Blog, Sucuri Blog). Community reaction has been consistent with standard WordPress plugin vulnerability disclosures, with security vendors recommending prompt updates.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."