Local File Inclusion Vulnerability in SiteOrigin Widgets Bundle
Authenticated attackers with contributor-level access can exploit a Local File Inclusion vulnerability in the SiteOrigin Widgets Bundle WordPress plugin to execute arbitrary PHP code via the REST API.
CVE search metadata
CVE search record: CVE-2026-92174. Severity: high. CVSS: 7.5. KEV: no. Product: Widgets Bundle (<= 1.73.2). Brief: Local File Inclusion Vulnerability in SiteOrigin Widgets Bundle. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92174/
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion (LFI) in all versions up to and including 1.73.2. This vulnerability is tracked as CVE-2026-92174. The flaw exists due to insecure handling of the 'theme' parameter within the plugin's widget preview functionality.
Authenticated users with contributor-level permissions or higher can exploit this by sending a crafted JSON payload to the '/wp-json/sowb/v1/widgets/previews' REST endpoint. The payload must include a legacy top-level 'theme' key combined with a non-empty 'columns' array. This combination allows the attacker to bypass field validation because the 'update_fields()' function fails to strictly validate the provided data against declared form fields. By supplying a path to an existing .php file on the server, the attacker can force the application to include and execute the target file, leading to unauthorized code execution and potential privilege escalation or sensitive data access.
Impact
Successful exploitation allows authenticated attackers with minimal privileges (contributor) to achieve remote code execution on the WordPress server. This can lead to full site compromise, unauthorized database access, or lateral movement within the hosting environment.
Recommendation
- Update the SiteOrigin Widgets Bundle plugin to a version patched against CVE-2026-92174.
- Audit WordPress user permissions to identify and restrict accounts with 'contributor' status or higher that may be untrusted.
- Monitor access logs for unauthorized or suspicious POST requests to the '/wp-json/sowb/v1/widgets/previews' endpoint, specifically looking for JSON payloads containing 'theme' and 'columns' keys.
Immediate actions
Patch SiteOrigin Widgets Bundle to the latest version
Mitigations
Update SiteOrigin Widgets Bundle to version > 1.73.2
CVE-2026-92174
Detection coverage 1
Detect CVE-2026-92174 Exploitation - Potential LFI in SiteOrigin Widgets Bundle
highDetects exploitation of CVE-2026-92174 by identifying POST requests to the widgets preview endpoint containing both 'theme' and 'columns' keys in the JSON body.
Detection queries are available on the platform. Get full rules →