CVE-2026-97348
SiteOrigin Widgets Bundle <= 1.74.3 - Authenticated (Contributor+) Arbitrary File Read via LESS Injection via [siteorigin_widget] Shortcode 'value' JSON Instance (design.colors LESS Variable)
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline โ which would reject non-hex color values โ is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.
| CWE | CWE-22 |
| Vendor | gpriday |
| Product | siteorigin widgets bundle |
| Published | Oct 10, 2026 |
Get instant alerts for gpriday siteorigin widgets bundle
Be the first to know when new medium vulnerabilities affecting gpriday siteorigin widgets bundle are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N