PLUGIN SECURITY

Is Widgetize Pages Light safe?

Drop widgets in page or post content area. Widgetized pages. Build your custom Responsive page layout in no time. No coding, easy and fun!

What this plugin does

  • Slug: widgetize-pages-light
  • Author: OTWthemes
  • 3000+ active installs
  • 84/100 rating (32 reviews on wordpress.org)
  • 261309 all-time downloads
  • On WordPress.org since 2012-08-20

custom sidebarsidebarwidgetize pagewidgetswidgets in page

Maintenance status

  • Latest known version: 3.0
  • Last updated: 2022-05-07 2:26pm GMT
  • Tested up to WordPress: 5.9.16

⚠ Widgetize Pages Light hasn't been updated in over 1577 days. An unmaintained plugin doesn't receive new security fixes, which is itself a security risk even without a known CVE.

Known vulnerabilities

4 known CVEs on file for Widgetize Pages Light. Reported between 2025 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-58805 Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.0 3.0 2025-09-05 ✓ fixed in latest
Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed) Cross-Site Request Forgery (CSRF) High 7.1 < 3.0 3.0 2025-06-05 ✓ fixed in latest
CVE-2025-32117 Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.0 3.0 2025-04-07 ✓ fixed in latest
Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.0 3.0 2025-01-06 ✓ fixed in latest
CVE-2025-22313 Widgetize Pages Light <= 3.0 - Reflected Cross-Site Scripting Unknown not specified no fix on file
CVE-2025-30995 Widgetize Pages Light <= 3.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting Unknown not specified no fix on file

How to fix it

Keep Widgetize Pages Light updated — 3.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

2 of the vulnerabilities above have no fixed version on file — there's no update that resolves them. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.