<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Widgets Bundle (&lt;= 1.73.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/widgets-bundle--1.73.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 06:23:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/widgets-bundle--1.73.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local File Inclusion Vulnerability in SiteOrigin Widgets Bundle</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92174/</link><pubDate>Fri, 02 Oct 2026 06:23:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92174/</guid><description>Authenticated attackers with contributor-level access can exploit a Local File Inclusion vulnerability in the SiteOrigin Widgets Bundle WordPress plugin to execute arbitrary PHP code via the REST API.</description><content:encoded><![CDATA[<p>The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion (LFI) in all versions up to and including 1.73.2. This vulnerability is tracked as CVE-2026-92174. The flaw exists due to insecure handling of the 'theme' parameter within the plugin's widget preview functionality.</p>
<p>Authenticated users with contributor-level permissions or higher can exploit this by sending a crafted JSON payload to the '/wp-json/sowb/v1/widgets/previews' REST endpoint. The payload must include a legacy top-level 'theme' key combined with a non-empty 'columns' array. This combination allows the attacker to bypass field validation because the 'update_fields()' function fails to strictly validate the provided data against declared form fields. By supplying a path to an existing .php file on the server, the attacker can force the application to include and execute the target file, leading to unauthorized code execution and potential privilege escalation or sensitive data access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers with minimal privileges (contributor) to achieve remote code execution on the WordPress server. This can lead to full site compromise, unauthorized database access, or lateral movement within the hosting environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the SiteOrigin Widgets Bundle plugin to a version patched against CVE-2026-92174.</li>
<li>Audit WordPress user permissions to identify and restrict accounts with 'contributor' status or higher that may be untrusted.</li>
<li>Monitor access logs for unauthorized or suspicious POST requests to the '/wp-json/sowb/v1/widgets/previews' endpoint, specifically looking for JSON payloads containing 'theme' and 'columns' keys.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>lfi</category><category>wordpress</category><category>vulnerability</category><category>rce</category></item></channel></rss>