CVE-2026-66709 is a Critical Remote Code Execution (RCE) vulnerability in CTX Feed plugin version 6.6.42 or earlier. The vulnerability has a CVSS score of 9.1. Administrators and users of CTX Feed plugin version 6.6.42 or earlier should be aware of this vulnerability and take necessary actions. Security teams and vulnerability management teams should prioritize immediate updates or mitigations. The CVE re [truncated]
A high-severity vulnerability, CVE-2026-39434, was discovered in the CTX Feed plugin, affecting versions up to 6.6.26. This vulnerability allows shop managers to inject PHP objects, potentially leading to code execution, data breaches, or other malicious activities. The CVSS score for this vulnerability is 7.2, indicating a high level of severity.