Description
The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_user_can() capability check for the ACTION_SAVE_SECTION case. Furthermore, the nonce is exposed to any authenticated user through the directly-accessible twiz-ajax.js.php file which loads WordPress and outputs the nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP code via the twiz_custom_logic POST parameter when saving a section with output choice 'twiz_logic_output'.
Published: 2026-09-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The Welcomizer WordPress plugin allows an attacker to execute arbitrary PHP code on the server. The flaw arises because an AJAX action that saves a section does not verify that the user has the required capability; a simple nonce is verified instead. The handler then uses PHP eval() to run the value of the twiz_custom_logic POST parameter, meaning any code controlled by a user with Subscriber or higher privileges can be run. The vulnerability is a classic code injection flaw classified as CWE‑94.

Affected Systems

WordPress sites that have the Welcomizer plugin installed in any release up to and including version 2.8.1 are affected. Susceptible installations include those that still use the 2.8.1 tag and any earlier releases; the problem is present in all pre‑2.9 code bases.

Risk and Exploitability

With a CVSS score of 8.8, this issue carries high severity. The EPSS score is less than 1 %, indicating that, while the vector exists, the probability of active exploitation in the wild is low at the time of measurement and the vulnerability is not yet listed in the CISA KEV catalog. Successful exploitation requires an authenticated user with at least Subscriber rights; once authenticated, the attacker can craft a payload in twiz_custom_logic, send it via the exposed AJAX endpoint, and have it evaluated and executed on the server.

Generated by OpenCVE AI on September 19, 2026 at 23:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Welcomizer plugin to the latest stable release if one exists beyond 2.8.1; if no newer release is available, consider uninstalling the plugin.
  • Remove or restrict the ability for Subscriber‑level users to execute the twiz_custom_logic parameter – for example, by disabling the ‘twiz_logic_output’ option or editing the plugin to enforce a stricter capability check on the AJAX handler.
  • Block external access to the twiz-ajax.php and twiz-ajax.js.php endpoints using server‑side rules (e.g., .htaccess redirects or Nginx location restrictions) so that the nonce and AJAX handler are no longer reachable by unauthorized users.

Generated by OpenCVE AI on September 19, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sebwordpress
Sebwordpress the Welcomizer
Wordpress
Wordpress wordpress
Vendors & Products Sebwordpress
Sebwordpress the Welcomizer
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_user_can() capability check for the ACTION_SAVE_SECTION case. Furthermore, the nonce is exposed to any authenticated user through the directly-accessible twiz-ajax.js.php file which loads WordPress and outputs the nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP code via the twiz_custom_logic POST parameter when saving a section with output choice 'twiz_logic_output'.
Title The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Sebwordpress The Welcomizer
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:23.048Z

Reserved: 2026-03-17T13:16:03.389Z

Link: CVE-2026-4327

cve-icon Vulnrichment

Updated: 2026-09-19T13:52:43.966Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:53.887

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-4327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:30Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')