CVE Database /
CVE-2026-27984
CVE · Critical
CVE-2026-27984 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-27984
|
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.0 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.0
|
< 4.2.0
|
4.2.0 |
2026-03-02 |
—
|
CVE-2026-27984
The Widget Options plugin has a critical vulnerability that allows malicious users with contributor or higher permissions to inject arbitrary code on the server, potentially leading to unauthorized actions. This flaw affects all versions of the plugin up to 4.1.3, making it susceptible to exploitation by authenticated attackers.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings