What the vulnerability does
01Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options allows OS Command Injection.This issue affects Widget Options: from n/a through <= 4.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
Widget Options versions up to 4.1.0 contain a command injection vulnerability that allows authenticated users with low privileges to execute arbitrary system commands on the server. The vulnerability has a wide scope of impact, potentially affecting confidentiality, integrity, and availability of the entire site. All users should update immediately to a patched version.
What an attacker can do
03Attacker Capabilities
Run arbitrary system commands on the server with the privileges of the web server process.
Potential impact on your site
04Site Impact
Any authenticated user can compromise the entire server, steal data, modify files, or take the site offline.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account on the site.
Key dates
06Disclosure timeline
February 14, 2025
CVE published
April 28, 2026
Record updated