
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2448 is a Local File Inclusion (LFI) vulnerability in the Page Builder by SiteOrigin plugin for WordPress, affecting all versions up to and including 2.33.5. The flaw exists in the locate_template() function and allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server. It was published on March 3, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, ENISA EUVD).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal) and stems from insufficient input validation in the locate_template() function within the plugin's post-loop widget (inc/widgets/post-loop.php, line 576). An authenticated attacker can supply a crafted path value that traverses outside the intended template directory, causing the server to include and execute arbitrary PHP files. If the attacker can also upload files (e.g., images with embedded PHP code), those files can be included via this vector to achieve remote code execution (Wordfence, Plugin Source).
Successful exploitation allows an attacker to bypass access controls, read sensitive server-side files, and execute arbitrary PHP code in the context of the web server process. This can lead to full compromise of the WordPress site, including theft of credentials and database contents, defacement, or use of the server as a pivot point for further attacks. The impact spans confidentiality, integrity, and availability — all rated High in the CVSS scoring (Wordfence, ENISA EUVD).
The vulnerability requires only Contributor-level authentication, a low privilege threshold on many WordPress sites that allow user registration or guest posting. The EPSS score is 0.001 (0.1%), indicating low current probability of exploitation in the wild, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data. No public proof-of-concept exploit code or active in-the-wild exploitation campaigns have been reported (Wordfence, Qualys).
locate_template() function with user-controllable input.../../../../uploads/malicious.php) as the template parameter to point to an attacker-controlled file on the server..jpg with <?php system($_GET['cmd']); ?>) using WordPress's media uploader.../ sequences or references to the uploads directory.wp-content/uploads/; newly created web shells or backdoors in the WordPress root or plugin directories.php, bash, curl, wget) executing system commands not typical of normal WordPress operation.Users should update the Page Builder by SiteOrigin plugin to a version beyond 2.33.5 that addresses this vulnerability — check the official WordPress plugin repository for the patched release. As an interim measure, site administrators can restrict Contributor-level user registration or disable the Post Loop widget functionality until the patch is applied. Additionally, enforcing strict file upload policies (e.g., blocking PHP execution in the uploads directory via server configuration) can reduce the risk of exploitation via uploaded files (Wordfence, Wordfence Weekly Report).
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 2–8, 2026, highlighting it as a notable LFI risk for sites with open contributor registration (Wordfence Weekly Report). Sucuri also referenced the vulnerability in their March 2026 patch roundup, reinforcing the recommendation to update the plugin promptly (Sucuri Blog). Checkmarx mentioned it in their AppSec weekly digest, and social media accounts such as RedPacketSecurity and TheHackerWire amplified the disclosure on Mastodon and Twitter/X (Checkmarx Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."