DECIPHERU · INTELLIGENCECVE

ByJulian Calvo, Ed.D., M.S.Founder, DecipherU
HIGHCVESeptember 19, 2026

CVE-2026-4327, The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i...

Source: nvd.nist.gov (CVE-2026-4327) · September 19, 2026
DecipherU Intelligence aggregates cybersecurity developments from government databases, official filings, and authoritative sources. The summary below is written by DecipherU and does not represent the views of the original source. For full details, follow the source link.

Summary

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_user_can() capability check for the ACTION_SAVE_SECTION case. Furthermore, the nonce is exposed to any authenticated user through the directly-accessible twiz-ajax.js.php file which loads WordPress and outputs the nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP code via the twiz_custom_logic POST parameter when saving a section with output choice 'twiz_logic_output'.

Relevant Roles

incident-respondersoc-analystsecurity-engineer

For the full cve details, visit the original source.

Read Original Source: nvd.nist.gov
Source: nvd.nist.gov, September 19, 2026. This summary is DecipherU's original writing. For complete details, follow the source link above. This page is for informational purposes only and does not constitute security advice.

Sources

  1. NIST National Vulnerability Database (NVD) · Authoritative CVE records and CVSS scoring.
  2. CISA Advisories · Public-domain US Cybersecurity and Infrastructure Security Agency alerts.
  3. DecipherU Live Feeds · DecipherU aggregates and curates these cybersecurity intelligence items.
Last verified: September 19, 2026?Report an inaccuracy
CVE-2026-4327, The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i... Cybersecurity Intelligence