Code Injection Vulnerability in Widget Wrangler by Jonathan Daggerhart
CVE-2026-25447

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 March 2026

What is CVE-2026-25447?

The Widget Wrangler plugin by Jonathan Daggerhart contains a Code Injection vulnerability that allows unauthorized users to execute arbitrary code. This security issue affects all versions of Widget Wrangler up to and including 2.3.9, potentially exposing websites to severe risks, including remote code execution. It highlights the importance of using the latest software versions to safeguard against such vulnerabilities.

Affected Version(s)

Widget Wrangler 0 <= 2.3.9

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NumeX | Patchstack Bug Bounty Program
.