CVE Database /
CVE-2026-54823
CVE · Critical
CVE-2026-54823 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-54823
|
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.9
|
< 4.2.4
|
4.2.4 |
2026-06-17 |
—
|
CVE-2026-54823
The Widget Options plugin for WordPress contains a critical security flaw that allows malicious users with contributor-level permissions or higher to inject arbitrary commands on the server, which can lead to unauthorized actions being performed remotely. This vulnerability affects all versions of the plugin prior to 4.2.3. The issue is particularly concerning due to its potential to enable attackers to execute code on the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings