Close Menu
SkytikSkytik

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 2025

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 2025

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 2025
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    SkytikSkytik
    • Home
    • AI Tools
    • Online Tools
    • Tech News
    • Guides
    • Reviews
    • SEO & Marketing
    • Social Media Tools
    SkytikSkytik
    Home»SEO & Marketing»Page Builder by SiteOrigin WordPress Vulnerability Affects Up To 500k Sites
    SEO & Marketing

    Page Builder by SiteOrigin WordPress Vulnerability Affects Up To 500k Sites

    AwaisBy AwaisMarch 4, 2026No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Page Builder by SiteOrigin WordPress Vulnerability Affects Up To 500k Sites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An advisory was published about a high-severity vulnerability discovered in the Page Builder by SiteOrigin WordPress plugin, which is installed on more than 500,000 websites. This is the third vulnerability discovered in the SiteOrigin Page Builder in 2026. The vulnerability is rated 8.8 on the CVSS severity scale.

    What The Plugin Does

    Page Builder by SiteOrigin is a drag-and-drop layout builder for WordPress. It allows site owners to create responsive, column-based page designs using standard WordPress widgets. Users can build pages visually without writing code.

    Because it works with most themes and does not require coding knowledge, it is widely used on business and personal websites.

    Requires Contributor-Level Access

    The vulnerability requires authentication. An attacker must have Contributor-level access or higher. A Contributor is one of the lowest WordPress user roles. Contributors can create and submit posts but cannot publish them. This means the vulnerability does not require administrator access, but it does require an account.

    Local File Inclusion Vulnerability

    The plugin is vulnerable to Local File Inclusion in all versions up to and including 2.33.5.

    Local File Inclusion means the plugin can be forced to load files from the server without properly restricting which files are allowed.

    The issue exists in the locate_template() function.

    What Went Wrong

    The plugin does not properly restrict which files can be included through the locate_template() function.

    That function should only load approved template files.

    What Attackers Can Do

    Because the restriction is missing, an authenticated attacker can cause the plugin to include arbitrary files that already exist on the server.

    If an attacker can upload a file to the server, they may be able to force the plugin to include that file and execute it as PHP code.

    According to the official Wordfence advisory:

    “The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

    This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.”

    Affected And Patched Versions

    The vulnerability affects Page Builder by SiteOrigins plugin versions: 2.33.5 and earlier. The issue has been fixed in version 2.34.0.

    Recommended Actions For Site Owners

    Site owners using Page Builder by SiteOrigin should update to version 2.34.0 or newer. If updating is not possible, disable the plugin until it can be updated.

    Featured Image by Shutterstock/Jan phanomphrai

    500k Affects builder page SiteOrigin Sites vulnerability WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Awais
    • Website

    Related Posts

    3 CMS Platforms Control 73% Of The Market & Shape Technical SEO Defaults

    March 17, 2026

    Google tests “Sponsored Shops” blocks in Shopping results

    March 16, 2026

    AI Search Barely Cites Syndicated News Or Press Releases

    March 16, 2026

    OpenAI tests Ads Manager as ChatGPT ad business takes shape

    March 16, 2026

    You’re Not Scaling Content. You’re Scaling Disappointment

    March 16, 2026

    7 organic content investments that drive ecommerce ROI

    March 16, 2026
    Leave A Reply Cancel Reply

    Top Posts

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 20250 Views

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 20250 Views

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 20250 Views
    Don't Miss

    3 CMS Platforms Control 73% Of The Market & Shape Technical SEO Defaults

    March 17, 2026

    Chris Green helped analyze 17 million websites and co-authored the latest SEO chapter for the…

    Top 7 Traackr Alternatives 2026

    March 17, 2026

    Frequency-Aware Planning and Execution Framework for All-in-One Image Restoration

    March 17, 2026

    Get threat intelligence to your team fast, in the tools they already use

    March 17, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Google tests “Sponsored Shops” blocks in Shopping results

    March 16, 2026

    AI Search Barely Cites Syndicated News Or Press Releases

    March 16, 2026
    Most Popular

    13 Trending Songs on TikTok in Nov 2025 (+ How to Use Them)

    November 18, 20257 Views

    How to watch the 2026 GRAMMY Awards online from anywhere

    February 1, 20263 Views

    Corporate Reputation Management Strategies | Sprout Social

    November 19, 20252 Views
    Our Picks

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 2025

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 2025

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer

    © 2025 skytik.cc. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.