{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/widgets-bundle--1.73.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siteorigin:widgets_bundle:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92174"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Widgets Bundle (\u003c= 1.73.2)"],"_cs_severities":["high"],"_cs_tags":["lfi","wordpress","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["SiteOrigin"],"content_html":"\u003cp\u003eThe SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion (LFI) in all versions up to and including 1.73.2. This vulnerability is tracked as CVE-2026-92174. The flaw exists due to insecure handling of the 'theme' parameter within the plugin's widget preview functionality.\u003c/p\u003e\n\u003cp\u003eAuthenticated users with contributor-level permissions or higher can exploit this by sending a crafted JSON payload to the '/wp-json/sowb/v1/widgets/previews' REST endpoint. The payload must include a legacy top-level 'theme' key combined with a non-empty 'columns' array. This combination allows the attacker to bypass field validation because the 'update_fields()' function fails to strictly validate the provided data against declared form fields. By supplying a path to an existing .php file on the server, the attacker can force the application to include and execute the target file, leading to unauthorized code execution and potential privilege escalation or sensitive data access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers with minimal privileges (contributor) to achieve remote code execution on the WordPress server. This can lead to full site compromise, unauthorized database access, or lateral movement within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the SiteOrigin Widgets Bundle plugin to a version patched against CVE-2026-92174.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user permissions to identify and restrict accounts with 'contributor' status or higher that may be untrusted.\u003c/li\u003e\n\u003cli\u003eMonitor access logs for unauthorized or suspicious POST requests to the '/wp-json/sowb/v1/widgets/previews' endpoint, specifically looking for JSON payloads containing 'theme' and 'columns' keys.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T06:23:08Z","date_published":"2026-10-02T06:23:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92174/","summary":"Authenticated attackers with contributor-level access can exploit a Local File Inclusion vulnerability in the SiteOrigin Widgets Bundle WordPress plugin to execute arbitrary PHP code via the REST API.","title":"Local File Inclusion Vulnerability in SiteOrigin Widgets Bundle","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92174/"}],"language":"en","title":"CraftedSignal Threat Feed - Widgets Bundle (\u003c= 1.73.2)","version":"https://jsonfeed.org/version/1.1"}