Impact
A directory traversal flaw in the SiteOrigin Widgets Bundle plugin for WordPress allows an authenticated contributor or higher to read any file on the server. The vulnerability resides in the get_instance_css function, which incorrectly processes an attacker‑supplied JSON instance passed through the [siteorigin_widget] shortcode. By bypassing the normal update()/sanitize_field_input() pipeline, a malicious contributor can supply a specially crafted ‘value’ field that resolves to a LESS variable pointing to arbitrary files via a directory traversal sequence. The result is a confidentiality breach, exposing sensitive configuration files, credentials, or other sensitive data stored on the host.
Affected Systems
SiteOrigin Widgets Bundle plugin for WordPress, versions 1.74.3 and all earlier releases, distributed by gpriday. Any site running one of these versions is vulnerable, regardless of the number of other plugins installed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑severity risk, and the EPSS score is not available, which suggests the exploitation probability is not currently quantified. Because the flaw requires authenticated access, a user with contributor or higher role can exploit the issue. The vulnerability is not listed in the CISA KEV catalog, implying no known broad exploitation campaigns yet. An attacker would need to upload a short code with a crafted JSON instance, and the plugin would process it without validating the ‘value’ field, allowing the directory traversal to fetch files from any location on the filesystem.
OpenCVE Enrichment