{"ok":true,"trend":{"id":706850,"platform":"mastodon","region":"global","key":"🟠 cve-2026-92174 - high (7.5) the siteorigin widgets bundle plugin for wordpress is vulnerable to local file inclusion i","title":"🟠 CVE-2026-92174 - High (7.5) The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion i","url":"https://mastodon.social/@thehackerwire/117370031800471667","first_seen":"2026-10-02T07:24:05.046293Z","last_seen":"2026-10-02T07:24:05.046293Z","last_rank":12,"peak_rank":12,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.66078125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A high-severity vulnerability, CVE-2026-92174 scored 7.5, has been disclosed in the SiteOrigin Widgets Bundle plugin for WordPress. All versions up to and including 1.73.2 are affected by a local file inclusion flaw via the 'theme' parameter, which could let authenticated attackers with contributor-level access include sensitive files. Site owners are being urged to update the plugin promptly.","why":"The flaw affects a widely used WordPress plugin, so administrators are scrambling to patch before exploitation.","tone":"neutral","entities":["SiteOrigin Widgets Bundle","WordPress","CVE-2026-92174"],"summarized_at":"2026-10-02T07:25:20.222075Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":959},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"WordPress plugin SiteOrigin Widgets Bundle hit by file inclusion flaw","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T07:24:05.046293Z","rank":12,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@thehackerwire/117370031800471667","author":"thehackerwire","title":null,"snippet":"🟠 CVE-2026-92174 - High (7.5) The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level…","posted_at":"2026-10-02T07:02:37.505000Z","likes":0}],"elsewhere":[],"window":"7d"}}