All verified exploits

CVE-2026-2448 SiteOrigin Page Builder Local File Inclusion

Deterministic high WordPress Added cve-verified-cve-2026-2448

Detects the Page Builder by SiteOrigin WordPress plugin at version 2.33.5 or earlier, where the post-loop widget's locate_template() function concatenates user-controlled template names with WP_PLUGIN_DIR without path traversal validation. A Contributor-level user can include and execute arbitrary PHP files on the server, enabling credential theft and remote code execution.

Related WordPress exploits

Is your app exploitable through CVE-2026-2448?

Scan your domain free