Impact
The Welcomizer WordPress plugin allows an attacker to execute arbitrary PHP code on the server. The flaw arises because an AJAX action that saves a section does not verify that the user has the required capability; a simple nonce is verified instead. The handler then uses PHP eval() to run the value of the twiz_custom_logic POST parameter, meaning any code controlled by a user with Subscriber or higher privileges can be run. The vulnerability is a classic code injection flaw classified as CWE‑94.
Affected Systems
WordPress sites that have the Welcomizer plugin installed in any release up to and including version 2.8.1 are affected. Susceptible installations include those that still use the 2.8.1 tag and any earlier releases; the problem is present in all pre‑2.9 code bases.
Risk and Exploitability
With a CVSS score of 8.8, this issue carries high severity. The EPSS score is less than 1 %, indicating that, while the vector exists, the probability of active exploitation in the wild is low at the time of measurement and the vulnerability is not yet listed in the CISA KEV catalog. Successful exploitation requires an authenticated user with at least Subscriber rights; once authenticated, the attacker can craft a payload in twiz_custom_logic, send it via the exposed AJAX endpoint, and have it evaluated and executed on the server.
OpenCVE Enrichment