HIGH
sebwordpress
CVE published 2026-09-19
CVE-2026-4327
The Welcomizer plugin for WordPress has a Remote Code Execution vulnerability in all versions up to and including 2.8.1. This vulnerability is caused by missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler, combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no cu [truncated]