Unauthorized Shortcode Execution in SiteOrigin Widgets Bundle Plugin for WordPress
CVE-2026-2127
5.4MEDIUM
What is CVE-2026-2127?
The SiteOrigin Widgets Bundle plugin for WordPress has a security flaw that allows authenticated attackers to execute arbitrary shortcodes. This is due to insufficient checks in the siteorigin_widget_preview_widget_action() function. Although the function verifies a nonce for requests, it neglects to validate the user's capabilities. As a result, a user with Subscriber-level access or higher can exploit the vulnerability by invoking the SiteOrigin_Widget_Editor_Widget through the preview endpoint. Furthermore, the nonce used in this process is publicly accessible, posing additional risks when the Post Carousel widget is present on the site.
Affected Version(s)
SiteOrigin Widgets Bundle 0 <= 1.70.4