---
id: CVE-2026-97348
title: >-
  The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory
  Traversal in all versions up to, and including, 1.74.3 via the
  get_instance_css function
summary: >-
  The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory
  Traversal in all versions up to, and including, 1.74.3 via the
  get_instance_css function. This makes it possible for authenticated attackers,
  with contributor-…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T07:16:42.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97348'
references:
  - url: >-
      https://github.com/siteorigin/so-widgets-bundle/compare/540f834469fe...bf80892709fb
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.74.3/base/inc/shortcode.php#L31
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.74.3/base/inc/shortcode.php#L51
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.74.3/base/siteorigin-widget.class.php#L1006
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.74.3/base/siteorigin-widget.class.php#L1117
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.74.3/base/siteorigin-widget.class.php#L1134
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.74.3/base/siteorigin-widget.class.php#L1148
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3724795/so-widgets-bundle/trunk/base/siteorigin-widget.class.php
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/500f18e6-14ca-4632-9317-5886fa2bb763?source=cve
    label: security@wordfence.com
tags:
  - nvd
ingestedAt: '2026-10-10T07:26:21.928Z'
---

## Overview

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — is bypassed entirely because the [siteorigin_widget] shortcode handler calls $the_widget->widget() directly on the attacker-supplied decoded JSON instance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
