Detects the Page Builder by SiteOrigin WordPress plugin at version 2.33.5 or earlier, where the post-loop widget's locate_template() function concatenates user-controlled template names with WP_PLUGIN_DIR without path traversal validation. A Contributor-level user can include and execute arbitrary PHP files on the server, enabling credential theft and remote code execution.
Is your app exploitable through CVE-2026-2448?
Scan your domain free