CVE · High

CVE-2026-2052 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2052 Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.3 Improper Control of Generation of Code ('Code Injection') High 8.8 < 4.2.3 4.2.3 2026-05-01

CVE-2026-2052

The Widget Options – Advanced Conditional Visibility plugin for WordPress is susceptible to Remote Code Execution across all versions up to 4.2.2 due to its use of eval() with user-provided Display Logic expressions, lacking proper filtering and authorization checks. Authenticated users with at least Contributor-level access can exploit this flaw by manipulating the extended_widget_opts_block attribute, potentially executing arbitrary code on the server. Partial mitigation was introduced in version 4.2.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.