Until you receive the patch, you can go to the plugin settings: Settings – Widget Options
And disable the Display Logic feature (of course, if you’re not using it).
This will completely close the vulnerability.
Also, I would like to point out that the vulnerability can only be exploited by authorized WordPress users.