Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gpriday
Gpriday siteorigin Widgets Bundle Wordpress Wordpress wordpress |
|
| Vendors & Products |
Gpriday
Gpriday siteorigin Widgets Bundle Wordpress Wordpress wordpress |
Wed, 18 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, 1.70.4. This is due to a missing capability check on the `siteorigin_widget_preview_widget_action()` function which is registered via the `wp_ajax_so_widgets_preview` AJAX action. The function only verifies a nonce (`widgets_action`) but does not check user capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes by invoking the `SiteOrigin_Widget_Editor_Widget` via the preview endpoint. The required nonce is exposed on the public frontend when the Post Carousel widget is present on a page, embedded in the `data-ajax-url` HTML attribute. | |
| Title | SiteOrigin Widgets Bundle <= 1.70.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T12:51:34.763Z
Reserved: 2026-02-06T19:20:41.302Z
Link: CVE-2026-2127
Updated: 2026-02-18T12:24:55.752Z
Status : Awaiting Analysis
Published: 2026-02-18T09:15:58.817
Modified: 2026-02-18T17:51:53.510
Link: CVE-2026-2127
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:32Z