Description
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.
Published: 2026-10-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read
Action: Patch Plugin
AI Analysis

Impact

A directory traversal flaw in the SiteOrigin Widgets Bundle plugin for WordPress allows an authenticated contributor or higher to read any file on the server. The vulnerability resides in the get_instance_css function, which incorrectly processes an attacker‑supplied JSON instance passed through the [siteorigin_widget] shortcode. By bypassing the normal update()/sanitize_field_input() pipeline, a malicious contributor can supply a specially crafted ‘value’ field that resolves to a LESS variable pointing to arbitrary files via a directory traversal sequence. The result is a confidentiality breach, exposing sensitive configuration files, credentials, or other sensitive data stored on the host.

Affected Systems

SiteOrigin Widgets Bundle plugin for WordPress, versions 1.74.3 and all earlier releases, distributed by gpriday. Any site running one of these versions is vulnerable, regardless of the number of other plugins installed.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate‑severity risk, and the EPSS score is not available, which suggests the exploitation probability is not currently quantified. Because the flaw requires authenticated access, a user with contributor or higher role can exploit the issue. The vulnerability is not listed in the CISA KEV catalog, implying no known broad exploitation campaigns yet. An attacker would need to upload a short code with a crafted JSON instance, and the plugin would process it without validating the ‘value’ field, allowing the directory traversal to fetch files from any location on the filesystem.

Generated by OpenCVE AI on October 10, 2026 at 08:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SiteOrigin Widgets Bundle to the latest version, which removes the vulnerable get_instance_css logic.
  • Restrict the use of the [siteorigin_widget] shortcode to administrators only, or remove the ability for contributor‑level users to add or edit widgets.
  • If the plugin is not required for site functionality, uninstall it to eliminate the attack surface.

Generated by OpenCVE AI on October 10, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.
Title SiteOrigin Widgets Bundle <= 1.74.3 - Authenticated (Contributor+) Arbitrary File Read via LESS Injection via [siteorigin_widget] Shortcode 'value' JSON Instance (design.colors LESS Variable)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:10.233Z

Reserved: 2026-09-24T12:27:03.747Z

Link: CVE-2026-97348

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:42.900

Modified: 2026-10-10T07:16:42.900

Link: CVE-2026-97348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:00:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')