Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-54823: Widget Options <= 4.2.3: Remote Code Execution via Contributor Input
CVE-2026-54823
Summary
An attacker can execute malicious code on your site if a contributor uploads a malicious file. This affects Widget Options plugin versions 4.2.3 and earlier. To fix this, update to the latest version of the plugin.
Original title
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
Original description
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
nvd CVSS3.1
9.9
Vulnerability type
CWE-94
Code Injection
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026