Executive brief
A vulnerability in the Widget Options plugin for WordPress allows users with low-level accounts, such as subscribers, to access sensitive information that should be restricted. This plugin is used to manage and customize how widgets appear on a website. An attacker could exploit this to retrieve internal metadata or other sensitive details, potentially aiding in further attacks against the site.
Technical details
The Widget Options plugin for WordPress (versions up to 4.0.1) contains a vulnerability classified as CWE-201: Insertion of Sensitive Information Into Sent Data. This flaw allows an authenticated attacker with 'Subscriber' level privileges to retrieve sensitive user meta-data that is normally restricted. The issue stems from improper data handling within the widget management components. An attacker can exploit this over the network without user interaction to gain unauthorized access to internal site information. The vulnerability is addressed in version 4.0.2.
Affected products
- MarketingFire (Extended Widget Options) Widget Options through 4.0.1
Timeline
- 2024-02-28: other: Reported by researcher
- 2024-06-06: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date