CVE · High

CVE-2023-4386 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4386, CVE-2023-4402 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1 Deserialization of Untrusted Data High 8.1 < 4.2.1 4.2.1 2023-09-13

CVE-2023-4386, CVE-2023-4402

The Essential Blocks plugin for WordPress through version 4.2.0 contains a PHP Object Injection vulnerability in the get_posts function that processes unserialized data from an untrusted source, allowing unauthenticated users to inject malicious PHP objects. While the plugin itself lacks a Property-Oriented Programming chain needed for direct exploitation, an attacker could leverage a POP chain from another installed plugin or theme to achieve dangerous outcomes such as arbitrary file deletion, unauthorized access to confidential information, or remote code execution. This vulnerability has been resolved in version 4.2.1 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.