• Resolved nlaustriat

    (@nlaustriat)


    Dear support,

    The IT départment of my client alert me today about a CVE hack problem in your plugin.. do you aware and please provide an update ?

    PLEASE HELP !

    HIGH 8.8 post-auth

    plugin :widget-options 4.2.5

    CVE-2026-2052

    Widget Options <= 4.2.2 – Authenticated (Contributor+) Remote Code Execution via Display Logic

    The page I need help with: [log in to see the link]

Viewing 1 replies (of 1 total)
  • Plugin Support Ryan from Marketing Fire

    (@atxlovesplugins)

    Hey @nlaustriat — no need to panic, you’re already safe here! 👍

    CVE-2026-2052 affects Widget Options versions 4.2.2 and below. You mentioned you’re running 4.2.5, which means the fix has been in place on your site for a while now — this vulnerability was fully patched back in version 4.2.3 (released in March), well before the CVE was even publicly disclosed in May.

    So to be clear:

    • ✅ Your version (4.2.5) is not vulnerable
    • ✅ No action needed on your end other than keeping the plugin updated as usual

    Your client’s IT department is likely working from a security feed that lists the CVE without checking the installed version against the patched version. You can point them to the Wordfence advisory, which confirms 4.2.3+ resolves it: https://www.wordfence.com/threat-intel/vulnerabilities/id/68023557-fc92-4cf6-96b4-405ff5a5fd5a

    We take security reports seriously and worked with the researchers to get this fully resolved and disclosed responsibly. If their IT team has any remaining questions, we’re happy to help.

Viewing 1 replies (of 1 total)

You must be logged in to reply to this topic.