CVE-2026-25447Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-29); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-29: 2Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-09: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-29: 203-2503-2904-09
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-03-292
Disclosure1General1
2026-04-091
PoC1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25447 Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affect… https://www.cve.org/CVERecord?id=CVE-2026-25447

    Post summary

    CVE-2026-25447 is disclosed as a code injection vulnerability in Widget Wrangler, but no PoC, exploit, patch, or active exploitation details are mentioned.

    00010259
    56.9K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-25447-widget-wrangler-version-2-3-9-high-vulnerability-proof-of-concept CVE-2026-25447 #WordPress plugin #vulnerability widget-wrangler #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for the WordPress Widget‑Wrangler CVE‑2026‑25447 has been posted, but no active exploitation, patch, or detailed technical data is disclosed.

    0000037
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-25447 Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affect… https://www.cve.org/CVERecord?id=CVE-2026-25447 ----- Traducción: CVE-2026-25447: Co… http://infoflow.cloud`

    Post summary

    The post only references CVE-2026-25447, noting its code injection nature and providing links to official CVE records, with no additional details on PoC, exploits, active use, or mitigation.

    0000025
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25447 - Critical Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: fr... https://www.thehackerwire.com/vulnerability/CVE-2026-25447/ https://t.co/9Hqkk4xwGE

    Post summary

    The post announces the discovery of CVE‑2026‑25447, an improper code‑generation vulnerability in Widget Wrangler that permits code injection, with no patch or exploit details provided.

    0000025
    145 followersView on X

Explore more