Executive brief
The Welcomizer WordPress plugin allows authenticated users with Subscriber-level access or higher to execute arbitrary PHP code on the web server. An attacker can inject malicious code through the plugin's section-saving feature, leading to complete server compromise and data theft. This affects all plugin versions up to 2.8.1.
Technical details
The plugin's AJAX handler (twiz_ajax_callback) performs nonce verification but lacks capability checks (current_user_can) for the 'savesection' action, and uses eval() to execute user-supplied 'custom logic' code. The nonce is exposed to authenticated users via twiz-ajax.js.php, allowing attackers with Subscriber access or above to inject arbitrary PHP via the twiz_custom_logic POST parameter when saving a section with 'twiz_logic_output' output choice.
Affected products
- The Welcomizer The Welcomizer up to and including 2.8.1
Timeline
- 2026-09-19: disclosed