9.8
CVSSv3

CVE-2023-4402

Published: 20/10/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated malicious users to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the malicious user to delete arbitrary files, retrieve sensitive data, or execute code.

Vulnerable Product Search on Vulmon Subscribe to Product

wpdeveloper essential blocks pro

wpdeveloper essential blocks

Exploits

WordPress Essential Blocks plugin versions 420 and below and Essential Blocks Pro versions 110 and below suffer from multiple PHP object injection vulnerabilities ...