Junglewise Threat Intelligence

CVE-2026-4327: The Welcomizer plugin for WordPress remote code execution

CVE-2026-4327 · Severity: high · CVSS 8.8 · Published 2026-09-19

Executive brief

The Welcomizer WordPress plugin allows authenticated users with Subscriber-level access or higher to execute arbitrary PHP code on the web server. An attacker can inject malicious code through the plugin's section-saving feature, leading to complete server compromise and data theft. This affects all plugin versions up to 2.8.1.

Technical details

The plugin's AJAX handler (twiz_ajax_callback) performs nonce verification but lacks capability checks (current_user_can) for the 'savesection' action, and uses eval() to execute user-supplied 'custom logic' code. The nonce is exposed to authenticated users via twiz-ajax.js.php, allowing attackers with Subscriber access or above to inject arbitrary PHP via the twiz_custom_logic POST parameter when saving a section with 'twiz_logic_output' output choice.

Affected products

  • The Welcomizer The Welcomizer up to and including 2.8.1

Timeline

  • 2026-09-19: disclosed

References