CVE-2023-4386, CVE-2023-4402
The Essential Blocks plugin for WordPress through version 4.2.0 contains a PHP Object Injection vulnerability in the get_posts function that processes unserialized data from an untrusted source, allowing unauthenticated users to inject malicious PHP objects. While the plugin itself lacks a Property-Oriented Programming chain needed for direct exploitation, an attacker could leverage a POP chain from another installed plugin or theme to achieve dangerous outcomes such as arbitrary file deletion, unauthorized access to confidential information, or remote code execution. This vulnerability has been resolved in version 4.2.1 and later.
Based on public CVE data (MITRE/NVD).