CVE-2026-92174 | SiteOrigin Widgets Bundle Plugin up to 1.73.2 on WordPress REST Endpoint previews update_fields theme unrestricted upload (EUVD-2026-91178)
A vulnerability was found in SiteOrigin Widgets Bundle Plugin up to 1.73.2 on WordPress. It has been declared as critical. The impacted element is the function update_fields of the file /wp-json/sowb/v1/widgets/previews of the component REST Endpoint. Executing a manipulation of the argument theme can lead to unrestricted upload.
This vulnerability is handled as CVE-2026-92174. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More