N/A
2026-02-17< 1.71.0
SiteOrigin Widgets Bundle <= 1.70.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
Minimum safe version
1.71.0
Update to 1.71.0 or later to address 12 fixable vulnerabilities
SiteOrigin Widgets Bundle <= 1.70.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
SiteOrigin Widgets Bundle <= 1.68.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-url` DOM Element Attribute
CVE-2024-54268
CVE-2024-5901
CVE-2024-5090
CVE-2024-4362
CVE-2024-1723
CVE-2024-1070
CVE-2024-1058
CVE-2024-0961
SiteOrigin Widgets Bundle <= 1.58.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-6295