WordPress · Create Block · CVE-2026-16623
**Name of the Vulnerable Software and Affected Versions**
Create Block WordPress plugin versions prior to 2.10.0
**Description**
Insufficient escaping of user-supplied text occurs before it is written into a generated PHP pattern file. This allows a multisite subsite administrator, who possesses the capability to perform this action but is restricted from editing PHP files, to inject and execute arbitrary PHP code on the server.
**Recommendations**
Update Create Block WordPress plugin to version 2.10.0 or later.