CVE-2026-0926Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[template_name]' parameter. This makes it possible for unauthenticated attackers to include and read arbitrary files or execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-02-19); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-19: 4Mentions · 2026-03-01: 1Mentions · 2026-03-17: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-17: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-01: 1Technical Details · 2026-02-19: 4Technical Details · 2026-03-01: 1Technical Details · 2026-03-17: 102-1903-0103-17
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-194
Disclosure3General1
2026-03-011
Patch1
2026-03-171
Disclosure1
Full discourse6 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-0926 - critical 🚨 Prodigy Commerce <= 3.3.0 - Local File Inclusion > Prodigy Commerce WordPress plugin <= 3.2.9 contains a local file inclusion caused by ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-0926 @pdnuclei #NucleiTemplates #cve

    Post summary

    The text discloses a local file inclusion vulnerability in Prodigy Commerce WordPress plugin (<=3.3.0), provides a technical link, but does not report active exploitation, exploit code, or patches.

    00033208
    901 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0926 The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' paramete… https://www.cve.org/CVERecord?id=CVE-2026-0926

    Post summary

    CVE-2026-0926 is a Local File Inclusion vulnerability in the Prodigy Commerce WordPress plugin (versions ≤3.2.9), with the vulnerability details disclosed but no PoC, exploit, patch, or evidence of active exploitation reported.

    00010323
    56.4K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-0926 — critical file inclusion flaw in the Prodigy Commerce WordPress plugin (≤ 3.2.9). https://nvd.nist.gov/vuln/detail/CVE-2026-0926 An unauthenticated Local File Inclusion via the template_name parameter lets attackers include or execute arbitrary files — potentially leading to full server compromise, data theft, or remote code execution. Why it matters: No login is needed and the bug scores 9.8 (critical), meaning attackers can exploit it remotely with low complexity. Fix/mitigation: Update the plugin to a secure version or remove it if unmaintained; validate file access and restrict uploads where possible. #WordPressSecurity #WebSecurity #CVE #Malware #FullPerimeterProtection #SilentRisk

    Post summary

    The post announces a critical LFI vulnerability in the Prodigy Commerce WordPress plugin, provides technical details, and offers a clear patch recommendation.

    0000058
    37 followersView on X
  • CVETodo@CveTodo
    General

    Certainly! Here's a comprehensive security assessment of CVE-2026-0926: #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-0926

    Post summary

    The post references CVE-2026-0926 with generic tags, but offers no concrete PoC, exploit, patch, or detailed technical information.

    0000031
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-0926 exposes all Prodigy Commerce WordPress sites to unauth RCE via LFI. No patch yet — disable plugin and monitor uploads now! 🔒 https://radar.offseq.com/threat/cve-2026-0926-cwe-98-improper-control-of-filename--2995b72c #OffSeq #WordPress #InfoSec https://t.co/e0bm50YKyd

    Post summary

    The tweet announces CVE‑2026‑0926 as a critical unauthenticated RCE via LFI affecting Prodigy Commerce WordPress sites, notes no patch exists yet, and recommends disabling the plugin and monitoring uploads.

    0000042
    265 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-0926: Prodigy Commerce &lt;= 3.2.9 - Unaut... Unfiltered LFI in Prodigy Commerce allows trivial path traversal via parameters[template_name], enabling server-side PHP... https://zerodaysignal.com/vulnerability/CVE-2026-0926 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑0926 is an unfiltered local file inclusion in Prodigy Commerce (≤3.2.9) that permits path traversal via the template_name parameter, potentially enabling server-side PHP execution; no patch, active exploitation, or false‑positive claims are mentioned.

    0000050
    131 followersView on X

Explore more