PT-2026-56310 · WordPress · Widget Logic Visual

·

CVE-2026-14158

·

Published

2026-07-08

·

Updated

2026-07-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Widget Logic Visual versions prior to 1.53
Description Authenticated attackers with subscriber-level access and above can achieve remote code execution on the server. The issue occurs during the widget-logic-update-conditional-tags AJAX action due to a missing capability check and nonce verification in the widget logic visual check visibility() function. Additionally, the nwlv[cod-tag] parameter is insufficiently sanitized before being stored and later processed by an eval() call, which executes the provided code.
Recommendations Update the plugin to a version newer than 1.52. As a temporary mitigation, restrict access to the widget-logic-update-conditional-tags AJAX action or limit user permissions to prevent subscribers from accessing widget settings.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14158

Affected Products

Widget Logic Visual