search
SiteOrigin Widgets Bundle
Trends
- 1WordPress plugin SiteOrigin Widgets Bundle hit by file inclusion flaw●🟠 CVE-2026-92174 - High (7.5) The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion i
A high-severity vulnerability, CVE-2026-92174 scored 7.5, has been disclosed in the SiteOrigin Widgets Bundle plugin for WordPress. All versions up to and including 1.73.2 are affected by a local file inclusion flaw via the 'theme' parameter, which could let authenticated attackers with contributor-level access include sensitive files. Site owners are being urged to update the plugin promptly.