Impact
The vulnerability is a Remote Code Execution flaw located in the Widget Options plugin for WordPress, affecting all releases up to and including version 4.2.3. It arises from a weakness that allows an attacker to execute arbitrary code on the web server, as identified by CWE-94. The impact is total loss of control over the affected WordPress site, enabling malicious actions such as data exfiltration, site defacement, or further compromise of the underlying server.
Affected Systems
The issue affects the MarketingFire Widget Options plugin for WordPress versions 4.2.3 and older. Users running any of those versions are vulnerable; upgrading to at least 4.2.4 removes the flaw.
Risk and Exploitability
The CVSS score of 9.9 indicates maximum severity, but the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the plugin’s nature and typical WordPress access, the likely attack vector is remote, possibly through unauthenticated or authenticated plugin interfaces. Once accessed, an attacker could run arbitrary server‑side code, fully compromising the affected WordPress installation.
OpenCVE Enrichment