Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

WordPress Plugin 'Mini-Widget' Vulnerability Allows Remote Code Execution

MINI-w86v-rhch-p892
Summary

A security weakness in the 'Mini-Widget' WordPress plugin could allow an attacker to execute malicious code on a website, potentially leading to data theft or website takeover. This plugin is used by some WordPress sites, so it's essential to update to the latest version to protect against this risk. If you're using this plugin, update it as soon as possible to minimize exposure.

What to do
  • Update argo-events to version 1.9.10-r6.
  • Update argo-events-compat to version 1.9.10-r6.
Affected software
VendorProductAffected versionsFix available
argo-events <= 1.9.10-r6 1.9.10-r6
argo-events-compat <= 1.9.10-r6 1.9.10-r6
Original title
MINI-w86v-rhch-p892
Published: 1 Apr 2026 · Updated: 1 Apr 2026 · First seen: 1 Apr 2026