PLUGIN SECURITY

Is So Widgets Bundle safe?

Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.

What this plugin does

  • Slug: so-widgets-bundle
  • Author: Greg - SiteOrigin
  • 400000+ active installs
  • 98/100 rating (134 reviews on wordpress.org)
  • 47737034 all-time downloads
  • On WordPress.org since 2014-06-01

blocksblogcontact formsliderwidgets

Maintenance status

  • Latest known version: 1.74.2
  • Last updated: 2026-07-24 10:44am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.0.0+

Known vulnerabilities

11 known CVEs on file for So Widgets Bundle.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-54268 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.64.1 Missing Authorization Medium 4.3 < 1.64.1 1.64.1 2024-12-10 ✓ fixed in latest
CVE-2024-5901 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.62.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.62.3 1.62.3 2024-07-30 ✓ fixed in latest
CVE-2024-5090 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.62.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.62.0 1.62.0 2024-06-10 ✓ fixed in latest
CVE-2024-4362 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.61.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.61.0 1.61.0 2024-05-21 ✓ fixed in latest
CVE-2024-1723 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.58.8 1.58.8 2024-03-04 ✓ fixed in latest
CVE-2024-1058 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.58.4 1.58.4 2024-02-12 ✓ fixed in latest
CVE-2024-1070 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.58.3 1.58.3 2024-02-12 ✓ fixed in latest
CVE-2024-0961 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.58.2 1.58.2 2024-01-29 ✓ fixed in latest
+ 6 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6295 SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.51.0 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.2 < 1.51.0 1.51.0 2023-11-27 ✓ fixed in latest
SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.69.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.69.0 1.69.0 0000-00-00 ✓ fixed in latest
SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.71.0 Unknown < 1.71.0 1.71.0 0000-00-00 ✓ fixed in latest
CVE-2024-0961 SiteOrigin Widgets Bundle < 1.58.2 - Contributor+ Stored XSS Unknown < 1.58.2 1.58.2 ✓ fixed in latest
CVE-2025-5585 SiteOrigin Widgets Bundle < 1.69.0 - Contributor+ Stored XSS via `data-url` DOM Element Attribute Unknown < 1.69.0 1.69.0 ✓ fixed in latest
CVE-2026-2127 SiteOrigin Widgets Bundle < 1.71.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution Unknown < 1.71.0 1.71.0 ✓ fixed in latest

How to fix it

Keep So Widgets Bundle updated — 1.74.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.