PLUGIN SECURITY
Is So Widgets Bundle safe?
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
What this plugin does
- Slug:
so-widgets-bundle - Author: Greg - SiteOrigin
- 400000+ active installs
- 98/100 rating (134 reviews on wordpress.org)
- 47737034 all-time downloads
- On WordPress.org since 2014-06-01
blocksblogcontact formsliderwidgets
Maintenance status
- Latest known version: 1.74.2
- Last updated: 2026-07-24 10:44am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.0.0+
Known vulnerabilities
11 known CVEs on file for So Widgets Bundle.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-54268 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.64.1 | Missing Authorization | Medium 4.3 | < 1.64.1 | 1.64.1 | 2024-12-10 | ✓ fixed in latest |
| CVE-2024-5901 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.62.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.62.3 | 1.62.3 | 2024-07-30 | ✓ fixed in latest |
| CVE-2024-5090 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.62.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.62.0 | 1.62.0 | 2024-06-10 | ✓ fixed in latest |
| CVE-2024-4362 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.61.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.61.0 | 1.61.0 | 2024-05-21 | ✓ fixed in latest |
| CVE-2024-1723 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.58.8 | 1.58.8 | 2024-03-04 | ✓ fixed in latest |
| CVE-2024-1058 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.58.4 | 1.58.4 | 2024-02-12 | ✓ fixed in latest |
| CVE-2024-1070 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.58.3 | 1.58.3 | 2024-02-12 | ✓ fixed in latest |
| CVE-2024-0961 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.58.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.58.2 | 1.58.2 | 2024-01-29 | ✓ fixed in latest |
+ 6 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-6295 | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.51.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.2 | < 1.51.0 | 1.51.0 | 2023-11-27 | ✓ fixed in latest |
| — | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.69.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.69.0 | 1.69.0 | 0000-00-00 | ✓ fixed in latest |
| — | SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.71.0 | — | Unknown | < 1.71.0 | 1.71.0 | 0000-00-00 | ✓ fixed in latest |
| CVE-2024-0961 | SiteOrigin Widgets Bundle < 1.58.2 - Contributor+ Stored XSS | — | Unknown | < 1.58.2 | 1.58.2 | — | ✓ fixed in latest |
| CVE-2025-5585 | SiteOrigin Widgets Bundle < 1.69.0 - Contributor+ Stored XSS via `data-url` DOM Element Attribute | — | Unknown | < 1.69.0 | 1.69.0 | — | ✓ fixed in latest |
| CVE-2026-2127 | SiteOrigin Widgets Bundle < 1.71.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution | — | Unknown | < 1.71.0 | 1.71.0 | — | ✓ fixed in latest |
How to fix it
Keep So Widgets Bundle updated — 1.74.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Contact Form 7 — 10000000+ active installs — 80/100 (2179) — max PHP 8.4
- Akismet Anti-spam: Spam Protection — 5000000+ active installs — 94/100 (1186) — max PHP 8.4
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More — 5000000+ active installs — 96/100 (14370)
- Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder — 700000+ active installs — 96/100 (791)
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder — 600000+ active installs — 96/100 (2119)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.