Impact
The WordPress Widget Logic plugin contains an improper control of code generation that allows an attacker to inject and execute arbitrary code. Classified as CWE-94, this flaw enables attackers to run malicious PHP scripts on the WordPress server, compromising the confidentiality, integrity, and availability of the site and potentially the underlying operating system.
Affected Systems
The vulnerability applies to all releases of the Widget Logic plugin from Widgetlogic.org up to and including version 6.0.5 on WordPress installations. Any site still running a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 9.9 denotes critical severity. Although the EPSS probability is less than 1% and the flaw is not listed in the CISA KEV catalog, the likely attack vector is inferred to be remote via crafted HTTP requests that activate the vulnerable widget code. Successful exploitation would permit an attacker to inject and execute arbitrary PHP code, potentially taking full control of the compromised site.
OpenCVE Enrichment