so-widgets-bundle < 1.51.0 - Admin+ Local File Inclusion
CVE-2023-6295
7.2HIGH
What is CVE-2023-6295?
The SiteOrigin Widgets Bundle plugin for WordPress prior to version 1.51.0 contains a vulnerability due to inadequate validation of user input. This oversight permits users with administrator privileges on Multisite installations to exploit Local File Inclusion (LFI) attacks. Consequently, attackers may manipulate paths fed to the include functions, potentially leading to unauthorized access to sensitive files on the server.
Affected Version(s)
SiteOrigin Widgets Bundle 0 < 1.51.0