MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #12

WordPress plugin SiteOrigin Widgets Bundle hit by file inclusion flaw

Original: 🟠 CVE-2026-92174 - High (7.5) The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion i

A high-severity vulnerability, CVE-2026-92174 scored 7.5, has been disclosed in the SiteOrigin Widgets Bundle plugin for WordPress. All versions up to and including 1.73.2 are affected by a local file inclusion flaw via the 'theme' parameter, which could let authenticated attackers with contributor-level access include sensitive files. Site owners are being urged to update the plugin promptly.

Why now: The flaw affects a widely used WordPress plugin, so administrators are scrambling to patch before exploitation.

SiteOrigin Widgets BundleWordPressCVE-2026-92174

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/706850