← WordPress Vulnerabilities
WordPress security by component

Widget Options

Widget Options is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Jun 25, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: widget-options

CVE-2026-54823: Widget Options: Code execution

Widget Options is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 4.2.3.

PublishedJun 25, 2026
Known safe version4.2.4
Safe version
Jun 25, 2026 CVE-2026-54823
Widget Options: Code execution
Widget Options is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 4.2.3.
4.2.4
CVE9.9
NVDPending
Jun 17, 2026 CVE-2024-35690
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.0.1.
4.0.2
CVE6.5
NVDPending
May 02, 2026 CVE-2026-2052
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets, Widget Options - Extended: Code execution
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets, Widget Options - Extended is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 4.2.2, <= 5.3.2.
> 4.2.2, > 5.3.2
CVE8.8
NVDPending
Mar 05, 2026 CVE-2026-27984
Widget Options: Code execution
Widget Options is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.0
NVDPending
Feb 14, 2025 CVE-2025-22630
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.9
NVDPending
Jan 21, 2025 CVE-2025-22722
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 31, 2024 CVE-2024-56219
Widget Options: A security weakness
Widget Options is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 28, 2024 CVE-2024-8672
Widget Options – The #1 WordPress Widget & Block Control Plugin: Code execution
Widget Options – The #1 WordPress Widget & Block Control Plugin is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.9
NVDPending