Sceawere
Vulnerability Detail
CVE-2026-97348UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiteOrigin Widgets Directory Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- gpriday
- Product
- SiteOrigin Widgets Bundle
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-10T07:16:42.900Z",
"pubdate": "2026-10-10T07:16:42.900Z",
"executiveSummary": "The SiteOrigin Widgets Bundle plugin for WordPress, in versions up to and including 1.74.3, is susceptible to a directory traversal vulnerability within the get_instance_css function.\nThis vulnerability allows authenticated attackers with contributor-level privileges or higher to read arbitrary files from the underlying server filesystem.\nThe flaw stems from a bypass of the plugin's standard security sanitization pipeline, specifically involving the mishandling of JSON-encoded instance data provided through the [siteorigin_widget] shortcode.\nSuccessful exploitation permits unauthorized access to sensitive server-side files, which may include configuration files, credentials, or other system-sensitive data.\nThe risk level is significant due to the ability to bypass intended input validation, and the exploitation requires authenticated access to the WordPress dashboard with at least contributor-level permissions.",
"technicalDetails": "The vulnerability resides in the get_instance_css function within the SiteOrigin Widgets Bundle, which is responsible for processing CSS for widgets. The flaw is triggered because the [siteorigin_widget] shortcode handler circumvents the normal plugin workflow.\nNormally, widget inputs are subjected to the update() and sanitize_field_input() methods, which are designed to validate and sanitize user-supplied data—for instance, ensuring that color-related fields strictly contain hex values.\nHowever, the [siteorigin_widget] shortcode handler calls the $the_widget->widget() method directly on attacker-supplied, decoded JSON instance data, effectively bypassing these critical security checks.\nBecause the sanitization pipeline is entirely bypassed, an attacker can supply malicious input that includes directory traversal sequences (e.g., ../ sequences) which are then processed by the get_instance_css function.\nThe function fails to adequately sanitize or restrict the path resolution, allowing an attacker to escape the intended directory scope and point to arbitrary files on the web server.\nWhen the application attempts to read the contents of the improperly sanitized path provided in the instance data, it retrieves the contents of the target file.\nThe attack flow follows these steps: 1) The attacker constructs a malicious JSON object containing a path traversal sequence. 2) The attacker submits this object via the [siteorigin_widget] shortcode. 3) The shortcode handler directly passes the malicious input to the widget logic without prior validation. 4) The get_instance_css function processes the path, resulting in the server reading the contents of the target file instead of the intended CSS source. 5) The sensitive file contents are rendered or otherwise exposed to the attacker.\nThis vulnerability is particularly dangerous as it allows for the exfiltration of sensitive files residing on the server, potentially exposing database credentials, environment variables, or sensitive source code, depending on the server's permissions.\nThe scope of the impact is constrained by the privileges of the web server user, but it provides a direct path to file disclosure for any file readable by the PHP process."
}