PT-2026-95787 · WordPress · Welcomizer

·

CVE-2026-4327

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Welcomizer plugin for WordPress versions prior to 2.8.2
Description Authenticated attackers with Subscriber-level access and above can achieve Remote Code Execution. The issue stems from missing authorization checks in the savesection handler of the twiz ajax callback AJAX action within the twiz-ajax.php endpoint. While the handler verifies a nonce, it fails to perform a current user can() capability check. Additionally, the nonce is exposed to authenticated users via the twiz-ajax.js.php file. This allows an attacker to inject arbitrary PHP code through the twiz custom logic parameter when the output choice is set to twiz logic output, which is then executed using the eval() function.
Recommendations Update The Welcomizer plugin to version 2.8.2 or later. As a temporary mitigation, restrict access to the twiz-ajax.php and twiz-ajax.js.php files for users with low-level privileges.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4327

Affected Products

Welcomizer