Sceawere

Vulnerability Detail

CVE-2026-97348UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiteOrigin Widgets Directory Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
gpriday
Product
SiteOrigin Widgets Bundle
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-10T07:16:42.900Z",
  "pubdate": "2026-10-10T07:16:42.900Z",
  "executiveSummary": "The SiteOrigin Widgets Bundle plugin for WordPress, in versions up to and including 1.74.3, is susceptible to a directory traversal vulnerability within the get_instance_css function.\nThis vulnerability allows authenticated attackers with contributor-level privileges or higher to read arbitrary files from the underlying server filesystem.\nThe flaw stems from a bypass of the plugin's standard security sanitization pipeline, specifically involving the mishandling of JSON-encoded instance data provided through the [siteorigin_widget] shortcode.\nSuccessful exploitation permits unauthorized access to sensitive server-side files, which may include configuration files, credentials, or other system-sensitive data.\nThe risk level is significant due to the ability to bypass intended input validation, and the exploitation requires authenticated access to the WordPress dashboard with at least contributor-level permissions.",
  "technicalDetails": "The vulnerability resides in the get_instance_css function within the SiteOrigin Widgets Bundle, which is responsible for processing CSS for widgets. The flaw is triggered because the [siteorigin_widget] shortcode handler circumvents the normal plugin workflow.\nNormally, widget inputs are subjected to the update() and sanitize_field_input() methods, which are designed to validate and sanitize user-supplied data—for instance, ensuring that color-related fields strictly contain hex values.\nHowever, the [siteorigin_widget] shortcode handler calls the $the_widget->widget() method directly on attacker-supplied, decoded JSON instance data, effectively bypassing these critical security checks.\nBecause the sanitization pipeline is entirely bypassed, an attacker can supply malicious input that includes directory traversal sequences (e.g., ../ sequences) which are then processed by the get_instance_css function.\nThe function fails to adequately sanitize or restrict the path resolution, allowing an attacker to escape the intended directory scope and point to arbitrary files on the web server.\nWhen the application attempts to read the contents of the improperly sanitized path provided in the instance data, it retrieves the contents of the target file.\nThe attack flow follows these steps: 1) The attacker constructs a malicious JSON object containing a path traversal sequence. 2) The attacker submits this object via the [siteorigin_widget] shortcode. 3) The shortcode handler directly passes the malicious input to the widget logic without prior validation. 4) The get_instance_css function processes the path, resulting in the server reading the contents of the target file instead of the intended CSS source. 5) The sensitive file contents are rendered or otherwise exposed to the attacker.\nThis vulnerability is particularly dangerous as it allows for the exfiltration of sensitive files residing on the server, potentially exposing database credentials, environment variables, or sensitive source code, depending on the server's permissions.\nThe scope of the impact is constrained by the privileges of the web server user, but it provides a direct path to file disclosure for any file readable by the PHP process."
}
CVE-2026-97348: SiteOrigin Widgets Directory Traversal (MEDIUM Severity, CVSS: 6.5) | Sceawere