CVE
CVE-2026-2127 — SiteOrigin Widgets Bundle < 1.71.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-2127 | SiteOrigin Widgets Bundle < 1.71.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution | — | Unknown | < 1.71.0 | 1.71.0 | — | — |
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.