Sceawere

Vulnerability Detail

CVE-2026-92174UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiteOrigin Widgets Bundle LFI Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
17h ago
Vendor
gpriday
Product
SiteOrigin Widgets Bundle
Attack Type
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T06:16:43.007Z",
  "pubdate": "2026-10-02T06:16:43.007Z",
  "executiveSummary": "The SiteOrigin Widgets Bundle plugin for WordPress, in versions up to and including 1.73.2, is susceptible to a Local File Inclusion (LFI) vulnerability.\nThis vulnerability stems from insecure handling of the 'theme' parameter within the REST API endpoint, allowing authenticated users with contributor-level privileges or higher to include and execute arbitrary PHP files residing on the server.\nSuccessful exploitation grants an attacker the ability to execute arbitrary PHP code, potentially leading to unauthorized access to sensitive data, full site compromise, or remote code execution (RCE) if the attacker can influence the filesystem content.\nThe attack is facilitated by the misconfiguration of the /wp-json/sowb/v1/widgets/previews REST endpoint, which fails to strictly validate input fields that are not explicitly declared.\nThe risk level is high due to the potential for complete control over the application environment and the relatively low barrier to entry for authenticated attackers with standard WordPress roles.",
  "technicalDetails": "The vulnerability resides within the /wp-json/sowb/v1/widgets/previews REST API endpoint of the SiteOrigin Widgets Bundle plugin. The root cause of the flaw is an insecure validation mechanism within the update_fields() function.\nWhen processing requests, the plugin's update_fields() function only performs validation on declared form fields. Because of this logic, malicious input provided to the API that includes a legacy top-level 'theme' key is not subjected to the intended security filters or sanitization routines.\nAn authenticated attacker with contributor-level access can craft a malicious JSON payload sent to the specified REST endpoint. By including a non-empty 'columns' array alongside the 'theme' parameter, the attacker can manipulate the internal state of the widget preview process.\nThis manipulation allows the attacker to point the 'theme' parameter to an arbitrary file path on the local filesystem. When the application processes the preview, it attempts to include the file specified in the 'theme' parameter as a PHP script.\nThe execution flow proceeds as follows: First, the attacker authenticates as a contributor or higher. Second, the attacker sends a POST request to /wp-json/sowb/v1/widgets/previews containing a JSON payload with the 'theme' parameter set to the target file path. Third, the plugin, failing to validate this undeclared field, proceeds to process the data.\nFourth, the application invokes file inclusion operations based on the user-supplied path. If the targeted file is a .php file, the server executes the code contained within that file with the privileges of the web server process.\nThis mechanism enables the execution of arbitrary PHP code if the attacker can place a malicious file on the server, such as through standard media uploads or other site functionalities. Consequently, an attacker can achieve full code execution, bypass WordPress access controls, and exfiltrate sensitive configuration data, including wp-config.php content or database credentials. The vulnerability effectively turns a predictable path inclusion into a high-impact RCE primitive, bypassing the intended design constraints of the widget preview system."
}
CVE-2026-92174: SiteOrigin Widgets Bundle LFI Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere