Directory Traversal Vulnerability in SiteOrigin Widgets Bundle Plugin for WordPress
CVE-2026-97348
6.5MEDIUM
What is CVE-2026-97348?
The SiteOrigin Widgets Bundle plugin for WordPress contains a Directory Traversal vulnerability that affects all versions up to and including 1.74.3. This vulnerability enables authenticated attackers with contributor-level access or higher to exploit the get_instance_css function, allowing them to read arbitrary files on the server. Consequently, sensitive information may be exposed as the vulnerability bypasses the standard update/sanitize_field_input() pipeline. The root cause lies in the execution of the widget's handling function, which directly processes attacker-supplied JSON data without proper validation of the input.
Affected Version(s)
SiteOrigin Widgets Bundle 0 <= 1.74.3