PT-2026-52412 · Marketing Fire+1 · Widget Options

·

CVE-2026-54823

·

Published

2026-06-17

·

Updated

2026-06-25

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Widget Options versions prior to 4.2.4
Description The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress allows authenticated attackers with Contributor-level access and above to execute arbitrary code on the server.
Recommendations Update the plugin to a version newer than 4.2.3.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54823

Affected Products

Widget Options