CVE-2026-2448: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2448 is a Local File Inclusion (LFI) vulnerability in the Page Builder by SiteOrigin plugin for WordPress, affecting all versions up to and including 2.33.5. The flaw exists in the locate_template() function and allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server. It was published on March 3, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal) and stems from insufficient input validation in the locate_template() function within the plugin's post-loop widget (inc/widgets/post-loop.php, line 576). An authenticated attacker can supply a crafted path value that traverses outside the intended template directory, causing the server to include and execute arbitrary PHP files. If the attacker can also upload files (e.g., images with embedded PHP code), those files can be included via this vector to achieve remote code execution (Wordfence, Plugin Source).

Impact

Successful exploitation allows an attacker to bypass access controls, read sensitive server-side files, and execute arbitrary PHP code in the context of the web server process. This can lead to full compromise of the WordPress site, including theft of credentials and database contents, defacement, or use of the server as a pivot point for further attacks. The impact spans confidentiality, integrity, and availability — all rated High in the CVSS scoring (Wordfence, ENISA EUVD).

Exploitability

The vulnerability requires only Contributor-level authentication, a low privilege threshold on many WordPress sites that allow user registration or guest posting. The EPSS score is 0.001 (0.1%), indicating low current probability of exploitation in the wild, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data. No public proof-of-concept exploit code or active in-the-wild exploitation campaigns have been reported (Wordfence, Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running Page Builder by SiteOrigin version 2.33.5 or earlier using tools like WPScan or Shodan queries targeting the plugin's readme file.
  2. Obtain Contributor Access: Register or compromise a Contributor-level (or higher) account on the target WordPress site.
  3. Identify Vulnerable Parameter: Navigate to a page or post using the SiteOrigin Post Loop widget, which invokes the locate_template() function with user-controllable input.
  4. Craft Malicious Payload: Supply a path traversal string (e.g., ../../../../uploads/malicious.php) as the template parameter to point to an attacker-controlled file on the server.
  5. Upload Malicious File (if needed): If direct PHP files cannot be uploaded, upload an image with embedded PHP code (e.g., a .jpg with <?php system($_GET['cmd']); ?>) using WordPress's media uploader.
  6. Trigger File Inclusion: Submit the crafted widget configuration, causing the server to include and execute the malicious file, resulting in arbitrary PHP code execution (Wordfence, Plugin Source).

Indicators of compromise

  • Logs: WordPress and web server access logs showing POST requests to page/post edit endpoints with unusual template path parameters containing ../ sequences or references to the uploads directory.
  • File System: Unexpected PHP files or images with embedded PHP code in wp-content/uploads/; newly created web shells or backdoors in the WordPress root or plugin directories.
  • Process: Unusual child processes spawned by the web server (e.g., php, bash, curl, wget) executing system commands not typical of normal WordPress operation.
  • Network: Outbound connections from the web server to unknown external IPs, potentially indicating reverse shell or data exfiltration activity following successful exploitation.

Mitigation and workarounds

Users should update the Page Builder by SiteOrigin plugin to a version beyond 2.33.5 that addresses this vulnerability — check the official WordPress plugin repository for the patched release. As an interim measure, site administrators can restrict Contributor-level user registration or disable the Post Loop widget functionality until the patch is applied. Additionally, enforcing strict file upload policies (e.g., blocking PHP execution in the uploads directory via server configuration) can reduce the risk of exploitation via uploaded files (Wordfence, Wordfence Weekly Report).

Community reactions

Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 2–8, 2026, highlighting it as a notable LFI risk for sites with open contributor registration (Wordfence Weekly Report). Sucuri also referenced the vulnerability in their March 2026 patch roundup, reinforcing the recommendation to update the plugin promptly (Sucuri Blog). Checkmarx mentioned it in their AppSec weekly digest, and social media accounts such as RedPacketSecurity and TheHackerWire amplified the disclosure on Mastodon and Twitter/X (Checkmarx Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management