PT-2026-67667 · WordPress · Create Block
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Create Block WordPress plugin versions prior to 2.10.0
Description
Insufficient escaping of user-supplied text occurs before it is written into a generated PHP pattern file. This allows a multisite subsite administrator, who possesses the capability to perform this action but is restricted from editing PHP files, to inject and execute arbitrary PHP code on the server.
Recommendations
Update Create Block WordPress plugin to version 2.10.0 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Create Block