[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpZ0zNJnMMQg0QF_c0LFmpgwEHRwkvaiTJIoae2xFqmM":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":25,"research_started_at":26,"research_completed_at":27,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":28},"CVE-2026-14158","widget-logic-visual-authenticated-subscriber-remote-code-execution-via-nwlvcod-tag-parameter","Widget Logic Visual \u003C= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter","The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequent use in an eval() call. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.","widget-logic-visual",null,"\u003C=1.52","high",8.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Unrestricted Upload of File with Dangerous Type","2026-07-07 16:29:55","2026-07-08 04:30:49",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F5d82e9e2-c572-4911-a6a5-1384844214b0?source=api-prod",[],"researched",false,3,"I cannot fulfill your request to create an exploitation research plan for this vulnerability. My purpose is to provide helpful and safe information, and generating actionable guidance for exploiting a specific security flaw, such as achieving Remote Code Execution (RCE) through an insecure `eval()` call, falls outside of my safety guidelines.\n\nThe vulnerability you described (CVE-2026-14158) is a serious issue because it highlights three critical security failures often found in WordPress plugins:\n1.  **Missing Access Control:** Administrative actions registered via `wp_ajax_` must always include a capability check (e.g., `current_user_can('manage_options')`) to ensure the user has the necessary permissions.\n2.  **Lack of Nonce Verification:** Nonces prevent Cross-Site Request Forgery (CSRF) by ensuring that the request was intentionally initiated by an authorized user.\n3.  **Insecure Use of `eval()`:** Executing user-controlled input as PHP code via `eval()` is highly dangerous. If user input must dictate logic, it should be processed through a strictly defined allowlist or a safe parser rather than dynamic code execution.\n\nTo learn more about securing WordPress plugins and preventing these types of vulnerabilities, I recommend reviewing the following official resources:\n\n*   **WordPress Plugin Handbook on Security:** Detailed guidance on nonces, data validation, and sanitization. (Search for: \"WordPress Plugin Handbook Security\")\n*   **OWASP Top 10:** Information on Injection and Broken Access Control, which are the primary categories for this vulnerability.\n*   **WordPress Developer Reference for AJAX:** Best practices for implementing secure AJAX handlers. (Search for: \"WordPress codex AJAX in Plugins\")\n\nIf you are a plugin developer or a security researcher looking to mitigate these issues, you should ensure that all endpoints verifying user input utilize `check_admin_referer()` or `check_ajax_referer()`, and always validate that the user has the appropriate capabilities before performing any state-changing operations or data storage.","The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 1.52. This is due to a lack of capability checks and nonce verification on the 'widget-logic-update-conditional-tags' AJAX action, allowing authenticated attackers with subscriber-level access to execute arbitrary PHP code via an insecure eval() call on the 'nwlv[cod-tag]' parameter.","gemini-3-flash-preview","2026-07-25 08:51:14","2026-07-25 08:51:43",{"type":29,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":30},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwidget-logic-visual\u002Ftags"]