CVE-2026-14158

Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter

highUnrestricted Upload of File with Dangerous Type
8.8
CVSS Score
8.8
CVSS Score
high
Severity
Unpatched
Patched in
N/A
Time to patch

Description

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequent use in an eval() call. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
High
Confidentiality
High
Integrity
High
Availability

Technical Details

Affected versions<=1.52
PublishedJuly 7, 2026
Last updatedJuly 8, 2026
Affected pluginwidget-logic-visual
Research Plan
Unverified

I cannot fulfill your request to create an exploitation research plan for this vulnerability. My purpose is to provide helpful and safe information, and generating actionable guidance for exploiting a specific security flaw, such as achieving Remote Code Execution (RCE) through an insecure `eval()` …

Show full research plan

I cannot fulfill your request to create an exploitation research plan for this vulnerability. My purpose is to provide helpful and safe information, and generating actionable guidance for exploiting a specific security flaw, such as achieving Remote Code Execution (RCE) through an insecure eval() call, falls outside of my safety guidelines.

The vulnerability you described (CVE-2026-14158) is a serious issue because it highlights three critical security failures often found in WordPress plugins:

  1. Missing Access Control: Administrative actions registered via wp_ajax_ must always include a capability check (e.g., current_user_can('manage_options')) to ensure the user has the necessary permissions.
  2. Lack of Nonce Verification: Nonces prevent Cross-Site Request Forgery (CSRF) by ensuring that the request was intentionally initiated by an authorized user.
  3. Insecure Use of eval(): Executing user-controlled input as PHP code via eval() is highly dangerous. If user input must dictate logic, it should be processed through a strictly defined allowlist or a safe parser rather than dynamic code execution.

To learn more about securing WordPress plugins and preventing these types of vulnerabilities, I recommend reviewing the following official resources:

  • WordPress Plugin Handbook on Security: Detailed guidance on nonces, data validation, and sanitization. (Search for: "WordPress Plugin Handbook Security")
  • OWASP Top 10: Information on Injection and Broken Access Control, which are the primary categories for this vulnerability.
  • WordPress Developer Reference for AJAX: Best practices for implementing secure AJAX handlers. (Search for: "WordPress codex AJAX in Plugins")

If you are a plugin developer or a security researcher looking to mitigate these issues, you should ensure that all endpoints verifying user input utilize check_admin_referer() or check_ajax_referer(), and always validate that the user has the appropriate capabilities before performing any state-changing operations or data storage.

Research Findings
Static analysis — not yet PoC-verified

Summary

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 1.52. This is due to a lack of capability checks and nonce verification on the 'widget-logic-update-conditional-tags' AJAX action, allowing authenticated attackers with subscriber-level access to execute arbitrary PHP code via an insecure eval() call on the 'nwlv[cod-tag]' parameter.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.