CVE · Critical

CVE-2026-27984 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-27984 Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.0 Improper Control of Generation of Code ('Code Injection') Critical 9.0 < 4.2.0 4.2.0 2026-03-02

CVE-2026-27984

The Widget Options plugin has a critical vulnerability that allows malicious users with contributor or higher permissions to inject arbitrary code on the server, potentially leading to unauthorized actions. This flaw affects all versions of the plugin up to 4.1.3, making it susceptible to exploitation by authenticated attackers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.