WordPress security by component
Widget Options
Plugin description
Widget Options is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Jun 25, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
widget-optionsLatest vulnerability
CVE-2026-54823: Widget Options: Code execution
Widget Options is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 4.2.3.
| Safe version |
|
||
|---|---|---|---|
| Jun 25, 2026 |
CVE-2026-54823
Widget Options: Code execution
Widget Options is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 4.2.3.
|
4.2.4 |
CVE9.9
NVDPending
|
| Jun 17, 2026 |
CVE-2024-35690
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.0.1.
|
4.0.2 |
CVE6.5
NVDPending
|
| May 02, 2026 |
CVE-2026-2052
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets, Widget Options - Extended: Code execution
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets, Widget Options - Extended is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 4.2.2, <= 5.3.2.
|
> 4.2.2, > 5.3.2 |
CVE8.8
NVDPending
|
| Mar 05, 2026 |
CVE-2026-27984
Widget Options: Code execution
Widget Options is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.0
NVDPending
|
| Feb 14, 2025 |
CVE-2025-22630
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.9
NVDPending
|
| Jan 21, 2025 |
CVE-2025-22722
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 31, 2024 |
CVE-2024-56219
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 28, 2024 |
CVE-2024-8672
Widget Options – The #1 WordPress Widget & Block Control Plugin: Code execution
Widget Options – The #1 WordPress Widget & Block Control Plugin is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.9
NVDPending
|