Title: Authenticated (Contributor+) Remote Code Execution via Display Logic
Last modified: July 31, 2026

---

# Authenticated (Contributor+) Remote Code Execution via Display Logic

 *  Resolved [nlaustriat](https://wordpress.org/support/users/nlaustriat/)
 * (@nlaustriat)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/authenticated-contributor-remote-code-execution-via-display-logic/)
 * Dear support,
 * The IT départment of my client alert me today about a CVE hack problem in your
   plugin.. do you aware and please provide an update ?
 * PLEASE HELP !
 * **HIGH** 8.8 post-auth
 * plugin :widget-options 4.2.5
 * CVE-2026-2052
 * Widget Options <= 4.2.2 – Authenticated (Contributor+) Remote Code Execution 
   via Display Logic
 * The page I need help with: _[[log in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fauthenticated-contributor-remote-code-execution-via-display-logic%2F%3Foutput_format%3Dmd&locale=en_US)
   to see the link]_

Viewing 1 replies (of 1 total)

 *  Plugin Support [Ryan from Marketing Fire](https://wordpress.org/support/users/atxlovesplugins/)
 * (@atxlovesplugins)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/authenticated-contributor-remote-code-execution-via-display-logic/#post-18980534)
 * Hey [@nlaustriat](https://wordpress.org/support/users/nlaustriat/) — no need 
   to panic, you’re already safe here! 👍
 * CVE-2026-2052 affects Widget Options versions **4.2.2 and below**. You mentioned
   you’re running **4.2.5**, which means the fix has been in place on your site 
   for a while now — this vulnerability was fully patched back in version 4.2.3 (
   released in March), well before the CVE was even publicly disclosed in May.
 * So to be clear:
    - ✅ Your version (4.2.5) is **not vulnerable**
    - ✅ No action needed on your end other than keeping the plugin updated as usual
 * Your client’s IT department is likely working from a security feed that lists
   the CVE without checking the installed version against the patched version. You
   can point them to the Wordfence advisory, which confirms 4.2.3+ resolves it: 
   [https://www.wordfence.com/threat-intel/vulnerabilities/id/68023557-fc92-4cf6-96b4-405ff5a5fd5a](https://www.wordfence.com/threat-intel/vulnerabilities/id/68023557-fc92-4cf6-96b4-405ff5a5fd5a)
 * We take security reports seriously and worked with the researchers to get this
   fully resolved and disclosed responsibly. If their IT team has any remaining 
   questions, we’re happy to help.

Viewing 1 replies (of 1 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fauthenticated-contributor-remote-code-execution-via-display-logic%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/widget-options/assets/icon-256x256.gif?rev=2513739)
 * [Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets](https://wordpress.org/plugins/widget-options/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/widget-options/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/widget-options/)
 * [Active Topics](https://wordpress.org/support/plugin/widget-options/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/widget-options/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/widget-options/reviews/)

 * 2 replies
 * 2 participants
 * Last reply from: [Ryan from Marketing Fire](https://wordpress.org/support/users/atxlovesplugins/)
 * Last activity: [1 week, 1 day ago](https://wordpress.org/support/topic/authenticated-contributor-remote-code-execution-via-display-logic/#post-18980534)
 * Status: resolved