CVE-2026-14158Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequent use in an eval() call. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-14158 (CVSS 8.8): Widget Logic Visual WordPress plugin vulnerable to remote code execution in versions up to 1.52. Update immediately if deployed. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/oty37lWpCp

    Post summary

    The tweet announces that the Widget Logic Visual WordPress plugin has a remote code execution flaw (CVSS 8.8) affecting versions up to 1.52 and urges users to update immediately.

    0000057
    91 followersView on X

Explore more