The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-92174 is a Local File Inclusion (LFI) vulnerability in the widely-used SiteOrigin Widgets Bundle plugin for WordPress, affecting all versions up to 1.73.2. The vulnerability exists in the 'theme' parameter and allows authenticated attackers with contributor-level privileges or higher to include and execute arbitrary PHP files on the server. This is a critical risk for WordPress sites because the SiteOrigin Widgets Bundle is installed on thousands of websites. An attacker with even basic contributor access can leverage this vulnerability to execute arbitrary PHP code, potentially leading to complete site compromise, data exfiltration, privilege escalation, and persistent backdoor installation. Organizations relying on this plugin must immediately patch to version 1.73.3 or later, and audit contributor-level access across their WordPress deployments.
While this CVE is not currently mapped to specific MITRE ATT&CK techniques, Casky's security skills powered by Claude AI with extended reasoning would detect the attack patterns associated with this vulnerability through behavioral analysis. Practitioners would observe suspicious file inclusion attempts through parameter manipulation (CWE-98 characteristic behavior), unexpected PHP execution from non-standard directories, and unusual file system access patterns originating from authenticated WordPress sessions. Casky's skill detection would flag attempts to manipulate the 'theme' parameter with path traversal sequences or file references, correlate those attempts with subsequent code execution artifacts, and identify lateral movement or data access attempts that follow successful exploitation—patterns consistent with Execution and Credential Access phases of an attack chain.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-92174. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation