Impact
The SiteOrigin Widgets Bundle plugin for WordPress contains a local file inclusion flaw in versions up to 1.73.2. A malicious actor who can authenticate as a contributor or higher can send a crafted widgetData payload to the /wp-json/sowb/v1/widgets/previews REST endpoint. The plugin’s update_fields() routine fails to validate the legacy top-level theme key when the columns array is non‑empty, allowing the attacker to specify an arbitrary .php file path via the theme parameter. Once included, the code runs with the permissions of the web server, enabling bypass of access controls, exfiltration of sensitive data, or full remote code execution if the attacker can bring an executable PHP file into the file system.
Affected Systems
Affected product is the SiteOrigin Widgets Bundle plugin for WordPress, version 1.73.2 or older, distributed by gpriday. Any site that has installed the plugin and has at least contributor‑level user accounts is vulnerable. The issue is contained within the plugin’s REST API handlers and does not affect other WordPress components directly.
Risk and Exploitability
The flaw has a CVSS score of 7.5. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, but the condition that a contributor or higher can exploit it means a wide pool of potential attackers. The attack requires authentication, yet the presence of many contributor users on a site expands the attack surface. Because the plugin can include and execute arbitrary PHP files, the impact ranges from privilege escalation to full server compromise.
OpenCVE Enrichment