CVE · Critical

CVE-2026-54823 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-54823 Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4 Improper Control of Generation of Code ('Code Injection') Critical 9.9 < 4.2.4 4.2.4 2026-06-17

CVE-2026-54823

The Widget Options plugin for WordPress contains a critical security flaw that allows malicious users with contributor-level permissions or higher to inject arbitrary commands on the server, which can lead to unauthorized actions being performed remotely. This vulnerability affects all versions of the plugin prior to 4.2.3. The issue is particularly concerning due to its potential to enable attackers to execute code on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.