Widget Context

Widget Context has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Widget Context has a vendor fix available, so running the current release closes it.

All of these findings were reported by normaandersonfrank. Widget Context is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Widget Context vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2026-7615

Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter

Read the full analysis

Vulnerability Records

1 records
Widget Context banner
Latestv1.4.0

Widget Context

Kaspars

Author

Kaspars

4.5(96)
90/100
Last Updated
2026-05-18 (3mo ago)
Active Installs
40,000+
Downloads
1,005,351
Requires WP
3.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2009-07-16 (17y ago)

Use Widget Context to show and hide widgets on certain sections of your site — front page, posts, pages, archives, search, etc. Use targeting by URLs (with wildcard support) for maximum flexibility. Premium Support Subscribe to our Premium Support service and get the PRO 🚀 version of the plugin for free when it’s launched! Your support enables consistent maintenance and new feature development, and is greatly appreciated. Contribute Suggest code improvements on GitHub. Report bugs and suggestions on WordPress.org forums. Help translate to your language. Documentation Widget visibility can be configured under individual widget settings under “Appearance → Widgets” in your WordPress administration area or through the widget editing interface in the Customizer. Target by URL The “Target by URL” is a powerful feature for targeting sections of your website based on the request URLs. It was inspired by a similar feature in the Drupal CMS. Use relative URLs such as page/sub-page instead of absolute URLs https://example.com/page/sub-page because relative URLs are more flexible and make the logic portable between different domains and server environments. Wildcards Use the wildcard symbol * for matching dynamic parts of the URL. For example: topic/widgets/* to match all posts in the widgets category, if your permalink structure is set to /topic/%category%/%postname%. page-slug/* to match all child pages of the page-slug parent page. Use a trailing ?* to capture URL with all query arguments such as utm_source, etc. For example, for every blog/post-slug also include blog/post-slug?*. Exclude by URL Specify URLs to ignore even if they’re matched by any of the other context rules. For example, enter example/sub-page to hide a widget on this page even when “All Posts” is selected under “Global Sections”.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C