Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.4
Unauthenticated users can execute malicious code on WordPress sites with SiteOrigin Widgets Bundle
CVE-2026-2127
Summary
A security flaw in the SiteOrigin Widgets Bundle plugin for WordPress allows attackers to execute unauthorized code on sites using the plugin, potentially leading to data theft or site compromise. To fix this issue, update the SiteOrigin Widgets Bundle plugin to version 1.71 or later, or remove the Post Carousel widget if an update is not possible.
Original title
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, 1.70.4. This is due to a missing capability chec...
Original description
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, 1.70.4. This is due to a missing capability check on the `siteorigin_widget_preview_widget_action()` function which is registered via the `wp_ajax_so_widgets_preview` AJAX action. The function only verifies a nonce (`widgets_action`) but does not check user capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes by invoking the `SiteOrigin_Widget_Editor_Widget` via the preview endpoint. The required nonce is exposed on the public frontend when the Post Carousel widget is present on a page, embedded in the `data-ajax-url` HTML attribute.
nvd CVSS3.1
5.4
Vulnerability type
CWE-862
Missing Authorization
- https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.70.4/base/in...
- https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.70.4/base/in...
- https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.70.4/widgets...
- https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.70.4/widgets...
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new...
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bf92c64b-ca76-4af7-a1e...
Published: 18 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026