Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates, CVE-2023-6623
- CVE, Research URL
- Home page URL
-
Security reports for Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
- Published on
- Jan 15, 2024
- Research Description
- The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.
- Affected versions
-
Min -, max 4.4.3.
- Status
-
vulnerable