Sceawere
Vulnerability Detail
CVE-2026-92174UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiteOrigin Widgets Bundle LFI Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 17h ago
- Vendor
- gpriday
- Product
- SiteOrigin Widgets Bundle
- Attack Type
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-02T06:16:43.007Z",
"pubdate": "2026-10-02T06:16:43.007Z",
"executiveSummary": "The SiteOrigin Widgets Bundle plugin for WordPress, in versions up to and including 1.73.2, is susceptible to a Local File Inclusion (LFI) vulnerability.\nThis vulnerability stems from insecure handling of the 'theme' parameter within the REST API endpoint, allowing authenticated users with contributor-level privileges or higher to include and execute arbitrary PHP files residing on the server.\nSuccessful exploitation grants an attacker the ability to execute arbitrary PHP code, potentially leading to unauthorized access to sensitive data, full site compromise, or remote code execution (RCE) if the attacker can influence the filesystem content.\nThe attack is facilitated by the misconfiguration of the /wp-json/sowb/v1/widgets/previews REST endpoint, which fails to strictly validate input fields that are not explicitly declared.\nThe risk level is high due to the potential for complete control over the application environment and the relatively low barrier to entry for authenticated attackers with standard WordPress roles.",
"technicalDetails": "The vulnerability resides within the /wp-json/sowb/v1/widgets/previews REST API endpoint of the SiteOrigin Widgets Bundle plugin. The root cause of the flaw is an insecure validation mechanism within the update_fields() function.\nWhen processing requests, the plugin's update_fields() function only performs validation on declared form fields. Because of this logic, malicious input provided to the API that includes a legacy top-level 'theme' key is not subjected to the intended security filters or sanitization routines.\nAn authenticated attacker with contributor-level access can craft a malicious JSON payload sent to the specified REST endpoint. By including a non-empty 'columns' array alongside the 'theme' parameter, the attacker can manipulate the internal state of the widget preview process.\nThis manipulation allows the attacker to point the 'theme' parameter to an arbitrary file path on the local filesystem. When the application processes the preview, it attempts to include the file specified in the 'theme' parameter as a PHP script.\nThe execution flow proceeds as follows: First, the attacker authenticates as a contributor or higher. Second, the attacker sends a POST request to /wp-json/sowb/v1/widgets/previews containing a JSON payload with the 'theme' parameter set to the target file path. Third, the plugin, failing to validate this undeclared field, proceeds to process the data.\nFourth, the application invokes file inclusion operations based on the user-supplied path. If the targeted file is a .php file, the server executes the code contained within that file with the privileges of the web server process.\nThis mechanism enables the execution of arbitrary PHP code if the attacker can place a malicious file on the server, such as through standard media uploads or other site functionalities. Consequently, an attacker can achieve full code execution, bypass WordPress access controls, and exfiltrate sensitive configuration data, including wp-config.php content or database credentials. The vulnerability effectively turns a predictable path inclusion into a high-impact RCE primitive, bypassing the intended design constraints of the widget preview system."
}