Vulnerability record · CVE-2019-16759 · published 24 September 2019
CVE-2019-16759: vBulletin 5.x widgetConfig code parameter remote code execution
VVbulletin · Vbulletin
vBulletin 5.x through 5.5.4 passes the widgetConfig[code] parameter from an ajax/render/widget_php routestring request into PHP code execution, allowing remote command execution. The flaw is pre-authentication and trivially reachable, so any exposed vulnerable forum is at immediate risk. It is listed in CISA KEV and has public exploit code, making it a high-value target for mass scanning.
Description
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with public exploit code, KEV listing, and near-certain EPSS probability makes this an urgent patch-or-mitigate case.
What it is
vBulletin 5.x through 5.5.4 passes the widgetConfig[code] parameter from an ajax/render/widget_php routestring request into PHP code execution, allowing remote command execution. The flaw is pre-authentication and trivially reachable, so any exposed vulnerable forum is at immediate risk. It is listed in CISA KEV and has public exploit code, making it a high-value target for mass scanning.
Impact
An unauthenticated attacker can execute arbitrary commands on the web server, leading to full compromise of the vBulletin host and any data or credentials it holds. This can be used for webshell deployment, data theft, or lateral movement into the hosting environment.
Attack surface
Reached over the network via an HTTP request to the ajax/render/widget_php endpoint with a crafted widgetConfig[code] parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Exploitation is confirmed and active: the CVE is in CISA KEV (added 2021-11-03), EPSS 30-day probability is 0.99728 (99.95th percentile), and multiple references are tagged Exploit, including public pre-auth RCE write-ups and media coverage of mass attacks.
What to do
- Upgrade vBulletin to a version later than 5.5.4 per vendor instructions; this is the only complete fix.
- If immediate patching is not possible, block or restrict access to the ajax/render/widget_php route at the WAF or reverse proxy.
- Remove or disable the PHP widget module if it is not required for site functionality.
- Isolate the vBulletin host from internal networks and limit outbound traffic to reduce post-exploitation impact.
- Rotate database, admin, and server credentials after confirming a clean state.
Detection
- Search web logs for requests to ajax/render/widget_php containing widgetConfig[code] or routestring parameters.
- Monitor for unexpected PHP processes, webshell files, or outbound connections originating from the vBulletin server.
- Alert on POST requests to ajax/render endpoints from IPs with no prior session or authentication.
- Review file integrity on the vBulletin webroot for modified or newly created PHP files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-16759 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "vBulletin PHP Module Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-16759 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16759), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.