Skip to content
Threat Feed
high advisory

Local File Inclusion Vulnerability in SiteOrigin Widgets Bundle

Authenticated attackers with contributor-level access can exploit a Local File Inclusion vulnerability in the SiteOrigin Widgets Bundle WordPress plugin to execute arbitrary PHP code via the REST API.

CVE search metadata

CVE search record: CVE-2026-92174. Severity: high. CVSS: 7.5. KEV: no. Product: Widgets Bundle (<= 1.73.2). Brief: Local File Inclusion Vulnerability in SiteOrigin Widgets Bundle. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92174/

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion (LFI) in all versions up to and including 1.73.2. This vulnerability is tracked as CVE-2026-92174. The flaw exists due to insecure handling of the 'theme' parameter within the plugin's widget preview functionality.

Authenticated users with contributor-level permissions or higher can exploit this by sending a crafted JSON payload to the '/wp-json/sowb/v1/widgets/previews' REST endpoint. The payload must include a legacy top-level 'theme' key combined with a non-empty 'columns' array. This combination allows the attacker to bypass field validation because the 'update_fields()' function fails to strictly validate the provided data against declared form fields. By supplying a path to an existing .php file on the server, the attacker can force the application to include and execute the target file, leading to unauthorized code execution and potential privilege escalation or sensitive data access.

Impact

Successful exploitation allows authenticated attackers with minimal privileges (contributor) to achieve remote code execution on the WordPress server. This can lead to full site compromise, unauthorized database access, or lateral movement within the hosting environment.

Recommendation

  • Update the SiteOrigin Widgets Bundle plugin to a version patched against CVE-2026-92174.
  • Audit WordPress user permissions to identify and restrict accounts with 'contributor' status or higher that may be untrusted.
  • Monitor access logs for unauthorized or suspicious POST requests to the '/wp-json/sowb/v1/widgets/previews' endpoint, specifically looking for JSON payloads containing 'theme' and 'columns' keys.

Immediate actions

Patch SiteOrigin Widgets Bundle to the latest version

IT Operations 48h

Mitigations

Update SiteOrigin Widgets Bundle to version > 1.73.2

immediate IT Operations

CVE-2026-92174

Detection coverage 1

Detect CVE-2026-92174 Exploitation - Potential LFI in SiteOrigin Widgets Bundle

high

Detects exploitation of CVE-2026-92174 by identifying POST requests to the widgets preview endpoint containing both 'theme' and 'columns' keys in the JSON body.

sigma tactics: initial_access techniques: T1203 sources: webserver

Detection queries are available on the platform. Get full rules →