Vulnerability in SiteOrigin Widgets Bundle — CVE-2026-97348
MediumSeverity
—Estimated exploit probability
400,000+ sitesInstalls
1.75.0Fixed in
What to do now
Update SiteOrigin Widgets Bundle to 1.75.0 or later.
Affected versions
- Everything up to and including 1.74.3
Affected: SiteOrigin Widgets Bundle (plugin, so-widgets-bundle)
What the vulnerability is
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.