PT-2026-95787 · WordPress · Welcomizer
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Welcomizer plugin for WordPress versions prior to 2.8.2
Description
Authenticated attackers with Subscriber-level access and above can achieve Remote Code Execution. The issue stems from missing authorization checks in the
savesection handler of the twiz ajax callback AJAX action within the twiz-ajax.php endpoint. While the handler verifies a nonce, it fails to perform a current user can() capability check. Additionally, the nonce is exposed to authenticated users via the twiz-ajax.js.php file. This allows an attacker to inject arbitrary PHP code through the twiz custom logic parameter when the output choice is set to twiz logic output, which is then executed using the eval() function.Recommendations
Update The Welcomizer plugin to version 2.8.2 or later.
As a temporary mitigation, restrict access to the
twiz-ajax.php and twiz-ajax.js.php files for users with low-level privileges.Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Welcomizer