Widget Context
Widget Context has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Widget Context has a vendor fix available, so running the current release closes it.
All of these findings were reported by normaandersonfrank. Widget Context is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-7615Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter
Read the full analysisVulnerability Records

Widget Context
Author
Kaspars
Use Widget Context to show and hide widgets on certain sections of your site — front page, posts, pages, archives, search, etc. Use targeting by URLs (with wildcard support) for maximum flexibility. Premium Support Subscribe to our Premium Support service and get the PRO 🚀 version of the plugin for free when it’s launched! Your support enables consistent maintenance and new feature development, and is greatly appreciated. Contribute Suggest code improvements on GitHub. Report bugs and suggestions on WordPress.org forums. Help translate to your language. Documentation Widget visibility can be configured under individual widget settings under “Appearance → Widgets” in your WordPress administration area or through the widget editing interface in the Customizer. Target by URL The “Target by URL” is a powerful feature for targeting sections of your website based on the request URLs. It was inspired by a similar feature in the Drupal CMS. Use relative URLs such as page/sub-page instead of absolute URLs https://example.com/page/sub-page because relative URLs are more flexible and make the logic portable between different domains and server environments. Wildcards Use the wildcard symbol * for matching dynamic parts of the URL. For example: topic/widgets/* to match all posts in the widgets category, if your permalink structure is set to /topic/%category%/%postname%. page-slug/* to match all child pages of the page-slug parent page. Use a trailing ?* to capture URL with all query arguments such as utm_source, etc. For example, for every blog/post-slug also include blog/post-slug?*. Exclude by URL Specify URLs to ignore even if they’re matched by any of the other context rules. For example, enter example/sub-page to hide a widget on this page even when “All Posts” is selected under “Global Sections”.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C