CVE-2026-15095 Overview
CVE-2026-15095 is a directory traversal vulnerability [CWE-22] in the Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress. The flaw affects all plugin versions up to and including 6.6.43. Authenticated attackers with shop manager privileges or higher can delete arbitrary files on the server through the provider parameter. Deleting critical WordPress files such as wp-config.php can force the site into setup mode, enabling attacker-controlled reconfiguration and potential remote code execution.
Critical Impact
Authenticated shop managers can traverse directories via the provider parameter and delete server files with whitelisted extensions, potentially leading to remote code execution.
Affected Products
- Product Feed Manager for WooCommerce – CTX Feed plugin for WordPress
- All versions up to and including 6.6.43
- WooCommerce sites running vulnerable CTX Feed installations
Discovery Timeline
- 2026-09-22 - CVE-2026-15095 published to NVD
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-15095
Vulnerability Analysis
The vulnerability resides in the CTX Feed plugin's REST API implementation. Exploitation requires two sequential authenticated REST API calls. The attacker first sends a request to /wp-json/ctxfeed/v1/make_feed/save_feed_config to persist a traversal payload containing ../ sequences in the provider parameter within the wp_options table. A second request to /wp-json/ctxfeed/v1/manage_feeds/delete_feed then triggers the PHP unlink() call against the attacker-controlled path.
The plugin applies an extension whitelist that limits deletion to files ending in csv, xml, tsv, xls, xlsx, json, or txt. Despite this constraint, attackers can target critical configuration and log files that share these extensions, disrupt site operation, or delete files whose removal restores WordPress to install mode.
Root Cause
The plugin fails to sanitize the provider parameter before it is stored and later concatenated into a filesystem path used by unlink(). Path components such as ../ are neither stripped nor normalized, allowing traversal outside the intended feed directory. The extension whitelist acts as a partial mitigation but does not address the underlying traversal weakness.
Attack Vector
The attack requires shop manager-level authentication or higher on the target WordPress site. An attacker with such privileges submits a crafted provider value through the save_feed_config REST endpoint, then invokes delete_feed to trigger file removal. Because the traversal payload persists in wp_options, deletion can be executed asynchronously from the initial injection. See the Wordfence Vulnerability Analysis and the WordPress ManageFeeds.php Code for the vulnerable code path.
// No verified exploit code is available.
// Refer to the Wordfence advisory and plugin source references for technical details.
Detection Methods for CVE-2026-15095
Indicators of Compromise
- REST API requests to /wp-json/ctxfeed/v1/make_feed/save_feed_config containing ../ or URL-encoded traversal sequences in the provider parameter.
- Subsequent requests to /wp-json/ctxfeed/v1/manage_feeds/delete_feed originating from the same authenticated session.
- Unexpected deletion of WordPress files with extensions such as .txt, .json, or .xml outside the plugin's feed directory.
- WordPress reverting to the install wizard, indicating deletion of wp-config.php or other bootstrap files.
Detection Strategies
- Inspect web server access logs for POST requests to the two CTX Feed REST endpoints followed closely in time by the same user agent or IP.
- Query the wp_options table for CTX Feed configuration entries containing traversal characters in provider fields.
- Alert on file deletion events targeting WordPress core files or plugin/theme directories via file integrity monitoring.
Monitoring Recommendations
- Enable WordPress REST API request logging and forward events to a centralized analytics platform for correlation.
- Monitor shop manager and administrator account activity for anomalous REST API usage patterns.
- Track filesystem changes under the WordPress installation root, particularly deletions of configuration and log files.
How to Mitigate CVE-2026-15095
Immediate Actions Required
- Update the CTX Feed plugin to a version newer than 6.6.43 as soon as a fix is available from the vendor.
- Audit all shop manager and administrator accounts, removing accounts that are no longer required.
- Rotate credentials for any accounts with shop manager access or higher.
- Review recent REST API traffic to the affected endpoints and inspect wp_options for traversal payloads.
Patch Information
Refer to the WordPress Change Set Review for the vendor's remediation commit. Site operators should upgrade the plugin through the WordPress admin dashboard or by replacing the plugin files with a patched release from the WordPress plugin repository.
Workarounds
- Deactivate and remove the CTX Feed plugin until a patched version is installed if the plugin is not business-critical.
- Restrict access to the /wp-json/ctxfeed/ REST namespace using a web application firewall rule that blocks traversal sequences in the provider parameter.
- Enforce least-privilege role assignments so that only trusted users hold the shop manager role.
- Deploy file integrity monitoring on WordPress core, plugin, and theme directories to detect unauthorized deletions.
# Example WAF rule concept: block traversal in the provider parameter
# (adapt to your WAF's syntax)
SecRule REQUEST_URI "@beginsWith /wp-json/ctxfeed/v1/" \
"chain,phase:2,deny,status:403,id:1015095,msg:'CTX Feed traversal attempt'"
SecRule ARGS:provider "@rx (\.\./|%2e%2e%2f)" "t:lowercase,t:urlDecodeUni"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
