CVE Database /
CVE-2025-22630
CVE · Critical
CVE-2025-22630 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-22630
|
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.1.1 |
Improper Neutralization of Special Elements used in a Command ('Command Injection') |
Critical
9.9
|
< 4.1.1
|
4.1.1 |
2025-02-11 |
—
|
CVE-2025-22630
The Widget Options plugin for WordPress has a critical security flaw that allows malicious users with at least contributor privileges to inject arbitrary commands on the hosting server in all versions prior to 4.1.0. This vulnerability enables an attacker to run unauthorized system operations, posing a significant threat to website security.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings