Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
Description
The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequent use in an eval() call. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HTechnical Details
<=1.52I cannot fulfill your request to create an exploitation research plan for this vulnerability. My purpose is to provide helpful and safe information, and generating actionable guidance for exploiting a specific security flaw, such as achieving Remote Code Execution (RCE) through an insecure `eval()` …
Show full research plan
I cannot fulfill your request to create an exploitation research plan for this vulnerability. My purpose is to provide helpful and safe information, and generating actionable guidance for exploiting a specific security flaw, such as achieving Remote Code Execution (RCE) through an insecure eval() call, falls outside of my safety guidelines.
The vulnerability you described (CVE-2026-14158) is a serious issue because it highlights three critical security failures often found in WordPress plugins:
- Missing Access Control: Administrative actions registered via
wp_ajax_must always include a capability check (e.g.,current_user_can('manage_options')) to ensure the user has the necessary permissions. - Lack of Nonce Verification: Nonces prevent Cross-Site Request Forgery (CSRF) by ensuring that the request was intentionally initiated by an authorized user.
- Insecure Use of
eval(): Executing user-controlled input as PHP code viaeval()is highly dangerous. If user input must dictate logic, it should be processed through a strictly defined allowlist or a safe parser rather than dynamic code execution.
To learn more about securing WordPress plugins and preventing these types of vulnerabilities, I recommend reviewing the following official resources:
- WordPress Plugin Handbook on Security: Detailed guidance on nonces, data validation, and sanitization. (Search for: "WordPress Plugin Handbook Security")
- OWASP Top 10: Information on Injection and Broken Access Control, which are the primary categories for this vulnerability.
- WordPress Developer Reference for AJAX: Best practices for implementing secure AJAX handlers. (Search for: "WordPress codex AJAX in Plugins")
If you are a plugin developer or a security researcher looking to mitigate these issues, you should ensure that all endpoints verifying user input utilize check_admin_referer() or check_ajax_referer(), and always validate that the user has the appropriate capabilities before performing any state-changing operations or data storage.
Summary
The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 1.52. This is due to a lack of capability checks and nonce verification on the 'widget-logic-update-conditional-tags' AJAX action, allowing authenticated attackers with subscriber-level access to execute arbitrary PHP code via an insecure eval() call on the 'nwlv[cod-tag]' parameter.
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.