OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-4327

HIGH · CVSS 8.8 EPSS 0.68% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution due to inadequate authorization checks in the AJAX handler, allowing authenticated users to execute arbitrary PHP code. This vulnerability affects all versions up to and including 2.8.1, enabling attackers with Subscriber-level access and above to exploit the flaw through the 'savesection' action. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-4327
Severity
HIGH
CVSS
8.8
EPSS
0.68%
WordPress

Original NVD Description

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_user_can() capability check for the ACTION_SAVE_SECTION case. Furthermore, the nonce is exposed to any authenticated user through the directly-accessible twiz-ajax.js.php file which loads WordPress and outputs the nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP code via the twiz_custom_logic POST parameter when saving a section with output choice 'twiz_logic_output'.