CVE-2019-12826
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- wpchef/widget logic
- Source
- cve@mitre.org
References
- https://dannewitz.ninja/posts/widget-logic-csrf-to-rceExploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2112753/widget-logicThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9403
- https://wpvulndb.com/vulnerabilities/9413
- https://dannewitz.ninja/posts/widget-logic-csrf-to-rceExploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2112753/widget-logicThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9403
- https://wpvulndb.com/vulnerabilities/9413
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.