« Volver al listado

Widget Options

Widget Options: vulnerabilidades y CVE

Widget Options tiene 5 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses3
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-54823Crítica (9.9)0.79%—25 jun 2026
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-2052Alta (8.8)0.77%—2 may 2026
The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic…
CVE-2025-10580Media (6.4)0.19%—25 oct 2025
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple functions in all versions up to, and including, 4.1.2 due to…
CVE-2025-22722Media (4.3)0.24%—21 ene 2025
Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.8.
CVE-2024-8672Crítica (9.9)44%—28 nov 2024
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.